CVE-2022-39801
CVE-2022-39801
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 sep 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
SAP SE · SAP GRC Access Control Emergency Access Management¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →