PT-2022-13747 · Sap · Sap Information System
Mrempy
·
Published
2022-04-06
·
Updated
2023-07-24
·
CVE-2022-1248
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP Information System version 1.0
Description
A critical issue was found, allowing an unauthenticated attacker to create a new admin account for the web application with a simple POST request to the "add admin.php" file, located at the "/SAP Information System/controllers/" endpoint.
Recommendations
For SAP Information System version 1.0, restrict access to the "/SAP Information System/controllers/add admin.php" endpoint to prevent unauthorized admin account creation until a fix is available.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Information System