First published: Tue Jun 14 2022(Updated: )
SAP Financial Consolidation - version 1010,?does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Sybase Adaptive Server Enterprise | =kernel_7.22 | |
SAP Sybase Adaptive Server Enterprise | =kernel_7.49 | |
SAP Sybase Adaptive Server Enterprise | =kernel_7.53 | |
SAP Sybase Adaptive Server Enterprise | =krnl64nuc_7.22 | |
SAP Sybase Adaptive Server Enterprise | =krnl64nuc_7.22ext | |
SAP Sybase Adaptive Server Enterprise | =krnl64nuc_7.49 | |
SAP Sybase Adaptive Server Enterprise | =krnl64uc_7.22 | |
SAP Sybase Adaptive Server Enterprise | =krnl64uc_7.22ext | |
SAP Sybase Adaptive Server Enterprise | =krnl64uc_7.49 | |
SAP Sybase Adaptive Server Enterprise | =krnl64uc_7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31595 is considered a critical vulnerability due to its ability to allow unauthorized privilege escalation.
To address CVE-2022-31595, update your SAP Financial Consolidation software to the latest version that contains the relevant security patches.
CVE-2022-31595 bypasses necessary authorization checks for authenticated users, permitting potential privilege escalations.
CVE-2022-31595 affects multiple versions of SAP Adaptive Server Enterprise, including kernel versions 7.22, 7.49, and 7.53.
Yes, due to privilege escalation from CVE-2022-31595, there is a significant risk of unauthorized access to sensitive data.