PT-2022-13747 · Sap · Sap Information System

Mrempy

·

Published

2022-04-06

·

Updated

2023-07-24

·

CVE-2022-1248

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP Information System version 1.0
Description A critical issue was found, allowing an unauthenticated attacker to create a new admin account for the web application with a simple POST request to the "add admin.php" file, located at the "/SAP Information System/controllers/" endpoint.
Recommendations For SAP Information System version 1.0, restrict access to the "/SAP Information System/controllers/add admin.php" endpoint to prevent unauthorized admin account creation until a fix is available.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-1248

Affected Products

Sap Information System