CVE Vulnerabilities

CVE-2022-31589

Published: Jun 14, 2022 | Modified: Jun 29, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

Affected Software

Name Vendor Start Version End Version
Erp_financial_accounting Sap 618 (including) 618 (including)
Erp_financial_accounting Sap 720 (including) 720 (including)
Erp_localization_for_cee_countries Sap c-cee_110_600 (including) c-cee_110_600 (including)
Erp_localization_for_cee_countries Sap c-cee_110_602 (including) c-cee_110_602 (including)
Erp_localization_for_cee_countries Sap c-cee_110_603 (including) c-cee_110_603 (including)
Erp_localization_for_cee_countries Sap c-cee_110_604 (including) c-cee_110_604 (including)
Erp_localization_for_cee_countries Sap c-cee_110_700 (including) c-cee_110_700 (including)
S/4hana Sap 100 (including) 100 (including)
S/4hana Sap 101 (including) 101 (including)
S/4hana Sap 102 (including) 102 (including)
S/4hana Sap 103 (including) 103 (including)
S/4hana Sap 104 (including) 104 (including)
S/4hana Sap 105 (including) 105 (including)
S/4hana Sap 106 (including) 106 (including)
S/4hana Sap 107 (including) 107 (including)
S/4hana Sap 108 (including) 108 (including)

References