CVE-2022-26104: Medium severity sap businessobjects financial consolidation vulnerability
Published Mar 8, 2022
·Updated
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
Affected Software
1 affected component
SAP Financial Consolidation=10.1
Event History
Mar 8, 2022
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26104?
CVE-2022-26104 has been assigned a medium severity rating due to the potential for unauthorized message alterations.
2
How do I fix CVE-2022-26104?
To mitigate CVE-2022-26104, ensure that proper authorization checks are implemented for updating homepage messages in SAP Financial Consolidation.
3
Which versions of SAP Financial Consolidation are affected by CVE-2022-26104?
CVE-2022-26104 affects SAP Financial Consolidation version 10.1.
4
What kind of attack does CVE-2022-26104 enable?
CVE-2022-26104 allows unauthorized users to alter the maintenance system message.
5
Is there a patch available for CVE-2022-26104?
SAP has released a patch for CVE-2022-26104 that addresses the authorization check vulnerability.