7.5
CVE-2022-41268
- EPSS 0.57%
- Veröffentlicht 13.12.2022 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:22:57
- Erkennungen
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Planning And Consolidation Version 200
SAP ≫ Business Planning And Consolidation Version 300
SAP ≫ Business Planning And Consolidation Version 750
SAP ≫ Business Planning And Consolidation Version 751
SAP ≫ Business Planning And Consolidation Version 752
SAP ≫ Business Planning And Consolidation Version 753
SAP ≫ Business Planning And Consolidation Version 754
SAP ≫ Business Planning And Consolidation Version 755
SAP ≫ Business Planning And Consolidation Version 756
SAP ≫ Business Planning And Consolidation Version 757
SAP ≫ Business Planning And Consolidation Version 810
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.57% | 0.427 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| SAP | 8.5 | 1.8 | 6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
https://launchpad.support.sap.com/#/notes/3271091