CVE-2022-39801 PUBLISHED CVSS 7.5 HIGH

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.

EPSS 0.40% · 60.7th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.40%
60.7th percentile

Affected Products

VendorProductVersions
sapaccess_control12
SAP SESAP GRC Access Control Emergency Access ManagementV1100_700, V1200_750, V1100_731

Timeline

References

Open in Interactive Console →