SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-29613

Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number.

MEDIUM 4.3EPSS 0.74%

Does this matter?

Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.

Description

Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.74% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
sap/employee self service
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.