Privilege Escalation Vulnerability in SAP Business Planning and Consolidation
CVE-2022-41268

8.5HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 December 2022

Summary

A vulnerability exists within specific SAP standard roles in SAP Business Planning and Consolidation. This flaw allows a malicious user to exploit a transaction code intended for customer use, potentially granting them unauthorized access. If successful, this could lead to an attacker escalating their privileges, enabling them to read, modify, or delete sensitive system data, posing significant risks to data confidentiality and integrity.

Affected Version(s)

Business Planning and Consolidation SAP_BW 750

Business Planning and Consolidation DWCORE 200

Business Planning and Consolidation CPMBPC 810

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.