PT-2022-15505 · Sap · Sap Erp Hcm Portugal

Published

2022-02-09

·

Updated

2022-10-27

·

CVE-2022-22535

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP ERP HCM Portugal versions 600 through 608
Description The issue concerns a report that reads payroll data of employees in a certain area without performing necessary authorization checks. This allows an attacker to access payroll information, although they cannot modify any data or cause availability impacts.
Recommendations For versions 600 through 608, consider restricting access to the affected report to minimize the risk of unauthorized data access until a fix is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-22535

Affected Products

Sap Erp Hcm Portugal