PT-2022-13747 · Sap · Sap Information System

·

CVE-2022-1248

·

Published

2022-04-06

·

Updated

2023-07-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP Information System version 1.0
Description A critical issue was found, allowing an unauthenticated attacker to create a new admin account for the web application with a simple POST request to the "add admin.php" file, located at the "/SAP Information System/controllers/" endpoint.
Recommendations For SAP Information System version 1.0, restrict access to the "/SAP Information System/controllers/add admin.php" endpoint to prevent unauthorized admin account creation until a fix is available.

Exploit

Fix

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1248

Affected Products

Sap Information System