First published: Tue Dec 13 2022(Updated: )
SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can lead to the exposure of data like financial reports.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-41274.
The title of this vulnerability is SAP Disclosure Management - version 10.1 allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data.
The severity of CVE-2022-41274 is medium.
The affected software for CVE-2022-41274 is SAP Disclosure Management version 10.1.
An authenticated attacker can exploit this vulnerability by exploiting certain misconfigured application endpoints to read sensitive data.