CVE-2022-41268

CVSS V2 None CVSS V3 None
Description
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Overview
  • CVE ID
  • CVE-2022-41268
  • Assigner
  • cna@sap.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-13T03:15:09
  • Last Modified Date
  • 2022-12-15T15:49:02
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:sap:business_planning_and_consolidation:200:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:300:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:750:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:751:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:752:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:753:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:754:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:755:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:756:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:757:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:business_planning_and_consolidation:810:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2022-12-13 03:18:02 Added to TrackCVE
2022-12-13 14:15:23 2022-12-13T03:15:09.667 2022-12-13T03:15:09 CVE Published Date updated
2022-12-13 14:15:23 2022-12-13T13:33:15 CVE Modified Date updated
2022-12-13 14:15:23 Received Awaiting Analysis Vulnerability Status updated
2022-12-13 17:21:22 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-15 16:17:53 2022-12-15T15:49:02 CVE Modified Date updated
2022-12-15 16:17:53 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-15 16:17:54 CPE Information updated