PT-2022-17672 · Sap · Sap Netweaver Application Server Abap

CVE-2022-26102

·

Published

2022-03-08

·

Updated

2022-10-06

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for ABAP versions 700, 701, 702, 731
Description The issue is due to a missing authorization check, allowing an authenticated attacker to access content on the start screen of any transaction within the same SAP system, even if they are not authorized for that transaction. This could expose information and, in the worst case, manipulate data before the start screen is executed, resulting in limited impact on confidentiality and integrity of the application.
Recommendations For versions 700, 701, 702, 731, update to a version that includes the necessary authorization checks to prevent unauthorized access to transactions. As a temporary workaround, consider restricting access to sensitive transactions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26102

Affected Products

Sap Netweaver Application Server Abap