CVE-2022-22542
Last modified
CVE-2022-22542 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private address fields of Employee Business Partners, to an actor that is not explicitly authorized to have access to that information, which could compromise Confidentiality.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private address fields of Employee Business Partners, to an actor that is not explicitly authorized to have access to that information, which could compromise Confidentiality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | S\/4hana | 104 |
| Sap | S\/4hana | 105 |
| Sap | S\/4hana | 106 |
References
- https://launchpad.support.sap.com/#/notes/3142092Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3142092Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22542?
How severe is CVE-2022-22542?
How do I fix CVE-2022-22542?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22537When a user opens a manipulated Tagged Image File Format (.t…6.5
- CVE-2022-22538When a user opens a manipulated Adobe Illustrator file forma…6.5
- CVE-2022-22539When a user opens a manipulated JPEG file format (.jpg, 2d.x…6.5
- CVE-2022-2254A user with administrative privileges in Distributed Data Sy…4.8
- CVE-2022-22540SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701…7.5
- CVE-2022-22541SAP BusinessObjects Business Intelligence Platform - version…6.5
- CVE-2022-22543SAP NetWeaver Application Server for ABAP (Kernel) and ABAP …7.5
- CVE-2022-22544Solution Manager (Diagnostics Root Cause Analysis Tools) - v…9.1
- CVE-2022-22545A high privileged user who has access to transaction SM59 ca…4.9
- CVE-2022-22546Due to improper HTML encoding in input control summary, an a…5.4
- CVE-2022-22547Simple Diagnostics Agent - versions 1.0 (up to version 1.57.…7.5
- CVE-2022-22549Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Cert…8.1
Are you affected by CVE-2022-22542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
