First published: Tue Dec 13 2022(Updated: )
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business Planning And Consolidation | =200 | |
Sap Business Planning And Consolidation | =300 | |
Sap Business Planning And Consolidation | =750 | |
Sap Business Planning And Consolidation | =751 | |
Sap Business Planning And Consolidation | =752 | |
Sap Business Planning And Consolidation | =753 | |
Sap Business Planning And Consolidation | =754 | |
Sap Business Planning And Consolidation | =755 | |
Sap Business Planning And Consolidation | =756 | |
Sap Business Planning And Consolidation | =757 | |
Sap Business Planning And Consolidation | =810 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41268 is a medium severity vulnerability that allows unauthorized transaction execution in certain SAP Business Planning and Consolidation roles.
To mitigate CVE-2022-41268, apply the recommended SAP security patches and restrict access to sensitive transaction codes.
CVE-2022-41268 affects users of SAP Business Planning and Consolidation versions 200, 300, and versions from 750 to 757.
A malicious user can exploit CVE-2022-41268 to execute unauthorized transactions within the SAP Business Planning and Consolidation environment.
CVE-2022-41268 is primarily a local attack vector requiring access to the SAP Business Planning and Consolidation system.