First published: Tue Jul 12 2022(Updated: )
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap S\/4hana | =101 | |
Sap S\/4hana | =102 | |
Sap S\/4hana | =103 | |
Sap S\/4hana | =104 | |
Sap S\/4hana | =105 | |
Sap S\/4hana | =106 | |
Sap Sapscore | =127 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31597 is a vulnerability found in SAP S/4HANA versions S4CORE 101, 102, 103, 104, 105, 106, and SAPSCORE 127 that allows a low privileged authenticated user to escalate their privileges and gain unauthorized access.
CVE-2022-31597 has a severity rating of 5.4, which is considered medium.
SAP S/4HANA versions S4CORE 101, 102, 103, 104, 105, 106, and SAPSCORE 127 are affected by CVE-2022-31597.
To fix CVE-2022-31597, apply the necessary patches and updates provided by SAP and follow their recommended security guidelines.
You can find more information about CVE-2022-31597 on the SAP Support Portal at [link1] and in the official SAP documentation at [link2].