CVE-2022-41268: High severity sap business planning and consolidation vulnerability
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAPBW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41268?
CVE-2022-41268 is a medium severity vulnerability that allows unauthorized transaction execution in certain SAP Business Planning and Consolidation roles.
How do I mitigate CVE-2022-41268?
To mitigate CVE-2022-41268, apply the recommended SAP security patches and restrict access to sensitive transaction codes.
Who is affected by CVE-2022-41268?
CVE-2022-41268 affects users of SAP Business Planning and Consolidation versions 200, 300, and versions from 750 to 757.
What actions can a malicious user take with CVE-2022-41268?
A malicious user can exploit CVE-2022-41268 to execute unauthorized transactions within the SAP Business Planning and Consolidation environment.
Is CVE-2022-41268 a local or remote attack vector?
CVE-2022-41268 is primarily a local attack vector requiring access to the SAP Business Planning and Consolidation system.