Privilege Escalation Vulnerability in SAP Business Planning and Consolidation
CVE-2022-41268
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 December 2022
What is CVE-2022-41268?
A vulnerability exists within specific SAP standard roles in SAP Business Planning and Consolidation. This flaw allows a malicious user to exploit a transaction code intended for customer use, potentially granting them unauthorized access. If successful, this could lead to an attacker escalating their privileges, enabling them to read, modify, or delete sensitive system data, posing significant risks to data confidentiality and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Planning and Consolidation SAP_BW 750
Business Planning and Consolidation DWCORE 200
Business Planning and Consolidation CPMBPC 810
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved