PT-2022-25776 · Sap · Sap Basis
Published
2022-12-13
·
Updated
2022-12-15
·
CVE-2022-41264
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP BASIS versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791
Description
The issue allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation, the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application.
Recommendations
For SAP BASIS versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, consider restricting access to the RFC function module to prevent unauthorized execution of system class methods.
As a temporary workaround, consider disabling the public methods of the system class until a patch is available.
Restrict access to system classes to minimize the risk of exploitation.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Basis