VYPR
High severity8.1NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026

CVE-2022-22530

CVE-2022-22530

Description

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.

Affected products

9
  • SAP/S\/4hana7 versions
    cpe:2.3:a:sap:s\/4hana:100:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:sap:s\/4hana:100:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:101:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:102:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:103:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:104:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:105:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:s\/4hana:106:*:*:*:*:*:*:*
  • SAP/S/4HANAllm-fuzzy
    Range: 100, 101, 102, 103, 104, 105, 106
  • SAP SE/SAP S/4HANAv5
    Range: 100

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.