CVE-2022-39801
Published on: Not Yet Published
Last Modified on: 10/01/2022 02:17:00 AM UTC
Certain versions of Access Control from Sap contain the following vulnerability:
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.
- CVE-2022-39801 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
SAP SE - SAP GRC Access Control Emergency Access Management version = V1100_700
- Affected Vendor/Software:
SAP SE - SAP GRC Access Control Emergency Access Management version = V1100_731
- Affected Vendor/Software:
SAP SE - SAP GRC Access Control Emergency Access Management version = V1200_750
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Improper error handling in CLA assistant can cause crash · Advisory · cla-assistant/cla-assistant · GitHub | github.com text/html |
![]() |
No Description Provided | launchpad.support.sap.com text/html |
![]() |
SAP Patch Day Blog | web.archive.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Sap | Access Control | 12 | All | All | All |
Application | Sap | Access Control | v1100_700 | All | All | All |
Application | Sap | Access Control | v1100_731 | All | All | All |
Application | Sap | Access Control | v1200_750 | All | All | All |
- cpe:2.3:a:sap:access_control:12:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:access_control:v1100_700:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:access_control:v1100_731:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:access_control:v1200_750:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-39801 : #SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a F… twitter.com/i/web/status/1… | 2022-09-13 16:08:25 |
![]() |
CVE-2022-39801 | 2022-09-13 16:38:34 |