VYPR
Unrated severityNVD Advisory· Published Jun 14, 2022· Updated Aug 3, 2024

CVE-2022-31589

CVE-2022-31589

Description

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

Affected products

4
  • SAP/SHAAMllm-create
  • SAP SE/SAP ERP, localization for CEE countries.v5
    Range: C-CEE 110_600
  • SAP SE/SAP Financialsv5
    Range: SAP_FIN 618
  • SAP SE/SAP S/4Hana Corev5
    Range: S4CORE 100

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.