First published: Wed Feb 09 2022(Updated: )
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Erp Human Capital Management | =600 | |
Sap Erp Human Capital Management | =604 | |
Sap Erp Human Capital Management | =608 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22535 is medium with a severity value of 6.5.
SAP ERP HCM Portugal versions 600, 604, and 608 are affected by CVE-2022-22535.
CVE-2022-22535 allows an attacker to read payroll data of employees in a certain area without performing necessary authorization checks, but they cannot modify or cause availability issues.
To fix CVE-2022-22535, apply the necessary patches and updates provided by SAP.
You can find more information about CVE-2022-22535 in the SAP note 3126489 and the SAP document fa865ea4-167e-0010-bca6-c68f7e60039b.