First published: Wed Feb 09 2022(Updated: )
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private address fields of Employee Business Partners, to an actor that is not explicitly authorized to have access to that information, which could compromise Confidentiality.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP S/4HANA | =104 | |
SAP S/4HANA | =105 | |
SAP S/4HANA | =106 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22542 is classified as critical due to the exposure of sensitive personal information.
To fix CVE-2022-22542, apply the latest patches provided by SAP for affected versions of S/4HANA.
CVE-2022-22542 affects SAP S/4HANA versions 104, 105, and 106.
CVE-2022-22542 exposes the private address and bank details of Employee Business Partners.
Actors who have unauthorized access can exploit CVE-2022-22542 to retrieve sensitive personal information.