PT-2022-17672 · Sap · Sap Netweaver Application Server Abap

Published

2022-03-08

·

Updated

2022-10-06

·

CVE-2022-26102

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for ABAP versions 700, 701, 702, 731
Description The issue is due to a missing authorization check, allowing an authenticated attacker to access content on the start screen of any transaction within the same SAP system, even if they are not authorized for that transaction. This could expose information and, in the worst case, manipulate data before the start screen is executed, resulting in limited impact on confidentiality and integrity of the application.
Recommendations For versions 700, 701, 702, 731, update to a version that includes the necessary authorization checks to prevent unauthorized access to transactions. As a temporary workaround, consider restricting access to sensitive transactions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-26102

Affected Products

Sap Netweaver Application Server Abap