8.5
CVE-2022-41268
- EPSS 0.26%
- Published 13.12.2022 03:15:09
- Last modified 21.11.2024 07:22:57
- Source cna@sap.com
- Teams watchlist Login
- Open Login
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Business Planning And Consolidation Version200
SAP ≫ Business Planning And Consolidation Version300
SAP ≫ Business Planning And Consolidation Version750
SAP ≫ Business Planning And Consolidation Version751
SAP ≫ Business Planning And Consolidation Version752
SAP ≫ Business Planning And Consolidation Version753
SAP ≫ Business Planning And Consolidation Version754
SAP ≫ Business Planning And Consolidation Version755
SAP ≫ Business Planning And Consolidation Version756
SAP ≫ Business Planning And Consolidation Version757
SAP ≫ Business Planning And Consolidation Version810
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.26% | 0.49 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
cna@sap.com | 8.5 | 1.8 | 6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.