CVE-2022-41273
Last modified
CVE-2022-41273 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the victim doesn’t suspect the threat, they click on the link, log in to SAP Sourcing and CLM and at this point, they get redirected to a malicious website. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the victim doesn’t suspect the threat, they click on the link, log in to SAP Sourcing and CLM and at this point, they get redirected to a malicious website.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Contract Lifecycle Manager | 1100 |
| Sap | Sourcing | 1100 |
References
- https://launchpad.support.sap.com/#/notes/3270399Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3270399Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41273?
How severe is CVE-2022-41273?
How do I fix CVE-2022-41273?
Are you affected by CVE-2022-41273?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
