CVE-2022-31589: Medium severity sap erp vulnerability
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31589?
CVE-2022-31589 has a medium severity rating due to improper authorization checks allowing excess access rights.
How do I fix CVE-2022-31589?
To fix CVE-2022-31589, apply the recommended patches provided by SAP for affected versions.
What systems are affected by CVE-2022-31589?
CVE-2022-31589 affects several versions of SAP ERP Financial Accounting and SAP S/4HANA as well as SAP ERP Localization for CEE Countries.
What type of vulnerability is CVE-2022-31589?
CVE-2022-31589 is categorized as an authorization-related vulnerability.
Can users exploit CVE-2022-31589 without authentication?
No, users must be authenticated to exploit the authorization flaws associated with CVE-2022-31589.