First published: Tue Jun 14 2022(Updated: )
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ERP | =618 | |
SAP ERP | =720 | |
SAP ERP Localization for CEE Countries | =c-cee_110_600 | |
SAP ERP Localization for CEE Countries | =c-cee_110_602 | |
SAP ERP Localization for CEE Countries | =c-cee_110_603 | |
SAP ERP Localization for CEE Countries | =c-cee_110_604 | |
SAP ERP Localization for CEE Countries | =c-cee_110_700 | |
SAP S/4HANA | =100 | |
SAP S/4HANA | =101 | |
SAP S/4HANA | =102 | |
SAP S/4HANA | =103 | |
SAP S/4HANA | =104 | |
SAP S/4HANA | =105 | |
SAP S/4HANA | =106 | |
SAP S/4HANA | =107 | |
SAP S/4HANA | =108 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31589 has a medium severity rating due to improper authorization checks allowing excess access rights.
To fix CVE-2022-31589, apply the recommended patches provided by SAP for affected versions.
CVE-2022-31589 affects several versions of SAP ERP Financial Accounting and SAP S/4HANA as well as SAP ERP Localization for CEE Countries.
CVE-2022-31589 is categorized as an authorization-related vulnerability.
No, users must be authenticated to exploit the authorization flaws associated with CVE-2022-31589.