← back
CVE-2022-31590

CVE-2022-31590

EPSS 0.2%CWE-428
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.2%KEV nãoPoC Patch
Lifecycle
14 Jun 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →