CVE-2022-41264
Summary
| CVE | CVE-2022-41264 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-13 03:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Basis | 7.31 | All | All | All |
| Application | Sap | Basis | 7.40 | All | All | All |
| Application | Sap | Basis | 7.50 | All | All | All |
| Application | Sap | Basis | 7.51 | All | All | All |
| Application | Sap | Basis | 7.52 | All | All | All |
| Application | Sap | Basis | 7.53 | All | All | All |
| Application | Sap | Basis | 7.54 | All | All | All |
| Application | Sap | Basis | 7.55 | All | All | All |
| Application | Sap | Basis | 7.56 | All | All | All |
| Application | Sap | Basis | 7.57 | All | All | All |
| Application | Sap | Basis | 7.89 | All | All | All |
| Application | Sap | Basis | 7.90 | All | All | All |
| Application | Sap | Basis | 7.91 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | www.sap.com | |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.