{ "id": "CVE-2022-39801", "sourceIdentifier": "cna@sap.com", "published": "2022-09-13T16:15:09.170", "lastModified": "2024-11-21T07:18:16.603", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application." }, { "lang": "es", "value": "SAP GRC Access control Emergency Access Management permite a un atacante autenticado acceder a una sesi\u00f3n de Firefighter incluso despu\u00e9s de haberla cerrado en Firefighter Logon Pad. Este ataque s\u00f3lo puede lanzarse dentro del firewall. Si es explotado con \u00e9xito, el atacante puede conseguir acceso a la sesi\u00f3n de administrador y comprometer completamente la aplicaci\u00f3n" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 1.6, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "cna@sap.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-287" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:sap:access_control:12:*:*:*:*:*:*:*", "matchCriteriaId": "C685DE70-CE9E-43D0-BCE5-A7B90444A13E" } ] } ] } ], "references": [ { "url": "https://launchpad.support.sap.com/#/notes/3237075", "source": "cna@sap.com", "tags": [ "Permissions Required", "Vendor Advisory" ] }, { "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html", "source": "cna@sap.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://launchpad.support.sap.com/#/notes/3237075", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Permissions Required", "Vendor Advisory" ] }, { "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }