CVE-2022-22531 Information

Description

The F0743 Create Single Payment application of SAP S/4HANA - versions 100 101 102 103 104 105 106 does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code resulting in sensitive information being disclosed or modified.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Reference

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=596902035 https://launchpad.support.sap.com/#/notes/3112928

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

NONE

Base Severity

8.1

Share on: