CVE-2022-32248Improper Input Validation in SE SAP S 4hana

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 46.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateJul 13

Description

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDsap/s_4hana6 versions+5
CVEListV5sap_se/sap_s_4hana6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-c6jw-hx26-7j5p: Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or2022-07-13
CVEList
CVE-2022-32248: Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or2022-07-12
CVE-2022-32248 — Improper Input Validation | cvebase