First published: Tue Mar 08 2022(Updated: )
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Financial Consolidation | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26104 has been assigned a medium severity rating due to the potential for unauthorized message alterations.
To mitigate CVE-2022-26104, ensure that proper authorization checks are implemented for updating homepage messages in SAP Financial Consolidation.
CVE-2022-26104 affects SAP Financial Consolidation version 10.1.
CVE-2022-26104 allows unauthorized users to alter the maintenance system message.
SAP has released a patch for CVE-2022-26104 that addresses the authorization check vulnerability.