PT-2022-15501 · Sap · Sap S/4Hana

Published

2022-01-14

·

Updated

2026-02-24

·

CVE-2022-22531

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP S/4HANA versions 100 through 106
Description The issue concerns the F0743 Create Single Payment application, which fails to check uploaded or downloaded files. This oversight allows an attacker with basic user rights to execute arbitrary script code, potentially leading to the disclosure or modification of sensitive information.
Recommendations For SAP S/4HANA versions 100 through 106, consider implementing additional file validation and sanitization measures to prevent the execution of arbitrary script code. As a temporary workaround, restrict access to the F0743 Create Single Payment application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-22531

Affected Products

Sap S/4Hana