VDB
CVE-2022-31597
CVE-2022-31597
PUBLISHED
CVSS 5.5 MEDIUM
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.
EPSS 0.14% · 34.5th percentile
Risk Scores
CVSS 2.0
5.5
EPSS Score
0.14%
34.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sap | s\/4hana | 101, 102, 106 |
| SAP SE | SAP S/4HANA | S4CORE 101, 103, 104 |
| sap | sapscore | 127 |
Exploit Intelligence
Timeline
- Jul 12, 2022 CVE Published
- Jul 13, 2022 EPSS Score
- Aug 30, 2022 EPSS Score
- Oct 16, 2022 EPSS Score
- Dec 2, 2022 EPSS Score
- Jan 18, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jul 26, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
- Oct 28, 2023 EPSS Score