Back to search
CVE-2022-31597
Published: Jul 12, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP S/4HANA | affected S4CORE 101affected 102affected 103affected 104affected 105+2 more versions |
Weaknesses (CWE)
References
https://launchpad.support.sap.com/#/notes/3213826
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now