CVE-2022-41264
Last modified
CVE-2022-41264 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application. . EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Basis | 7.31 |
| Sap | Basis | 7.40 |
| Sap | Basis | 7.50 |
| Sap | Basis | 7.51 |
| Sap | Basis | 7.52 |
| Sap | Basis | 7.53 |
| Sap | Basis | 7.54 |
| Sap | Basis | 7.55 |
| Sap | Basis | 7.56 |
| Sap | Basis | 7.57 |
| Sap | Basis | 7.89 |
| Sap | Basis | 7.90 |
| Sap | Basis | 7.91 |
References
- https://launchpad.support.sap.com/#/notes/3268172Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3268172Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41264?
How severe is CVE-2022-41264?
How do I fix CVE-2022-41264?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41259SAP SQL Anywhere - version 17.0, allows an authenticated att…6.5
- CVE-2022-4126Use of Default Password vulnerability in ABB RCCMD on Window…9.8
- CVE-2022-41260SAP Financial Consolidation - version 1010, does not suffici…6.1
- CVE-2022-41261SAP Solution Manager (Diagnostic Agent) - version 7.20, allo…5.5
- CVE-2022-41262Due to insufficient input validation, SAP NetWeaver AS Java …6.1
- CVE-2022-41263Due to a missing authentication check, SAP Business Objects …4.3
- CVE-2022-41266Due to a lack of proper input validation, SAP Commerce Webse…6.1
- CVE-2022-41267SAP Business Objects Platform - versions 420, and 430, allow…8.8
- CVE-2022-41268In some SAP standard roles in SAP Business Planning and Cons…7.5
- CVE-2022-4127A NULL pointer dereference issue was discovered in the Linux…5.5
- CVE-2022-41271An unauthenticated user can attach to an open interface expo…9.4
- CVE-2022-41272An unauthenticated attacker over the network can attach to a…8.6
Are you affected by CVE-2022-41264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
