CVE-2022-39801
Summary
| CVE | CVE-2022-39801 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-13 16:15:00 UTC |
| Updated | 2022-10-01 02:17:00 UTC |
| Description | SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Access Control | 12 | All | All | All |
| Application | Sap | Access Control | v1100_700 | All | All | All |
| Application | Sap | Access Control | v1100_731 | All | All | All |
| Application | Sap | Access Control | v1200_750 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Improper error handling in CLA assistant can cause crash · Advisory · cla-assistant/cla-assistant · GitHub | MISC | github.com | |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| Access Denied | MISC | www.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.