CVE Published: 12/07/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: sap |
Vendor: SAP SE |
Product: SAP S/4HANA Status : PUBLISHED
CVE-2022-31597 Description
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.