CVE-2022-22535: Medium severity sap erp vulnerability
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22535?
The severity of CVE-2022-22535 is medium with a severity value of 6.5.
Which SAP ERP HCM Portugal versions are affected by CVE-2022-22535?
SAP ERP HCM Portugal versions 600, 604, and 608 are affected by CVE-2022-22535.
What is the impact of CVE-2022-22535?
CVE-2022-22535 allows an attacker to read payroll data of employees in a certain area without performing necessary authorization checks, but they cannot modify or cause availability issues.
How can I fix CVE-2022-22535?
To fix CVE-2022-22535, apply the necessary patches and updates provided by SAP.
Where can I find more information about CVE-2022-22535?
You can find more information about CVE-2022-22535 in the SAP note 3126489 and the SAP document fa865ea4-167e-0010-bca6-c68f7e60039b.