CVE-2022-41274
Last modified
CVE-2022-41274 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can lead to the exposure of data like financial reports.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can lead to the exposure of data like financial reports.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Disclosure Management | 10.1 |
References
- https://launchpad.support.sap.com/#/notes/3266846Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3266846Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41274?
How severe is CVE-2022-41274?
How do I fix CVE-2022-41274?
Are you affected by CVE-2022-41274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
