PT-2022-15501 · Sap · Sap S/4Hana
Published
2022-01-14
·
Updated
2026-02-24
·
CVE-2022-22531
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP S/4HANA versions 100 through 106
Description
The issue concerns the F0743 Create Single Payment application, which fails to check uploaded or downloaded files. This oversight allows an attacker with basic user rights to execute arbitrary script code, potentially leading to the disclosure or modification of sensitive information.
Recommendations
For SAP S/4HANA versions 100 through 106, consider implementing additional file validation and sanitization measures to prevent the execution of arbitrary script code. As a temporary workaround, restrict access to the F0743 Create Single Payment application to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap S/4Hana