HIGH🇵🇱 Wersja polska

CVE-2022-22530

CVSS 8.1v3.1pub. 2022-01-14upd. 2026-02-24

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
  • Sap S\/4hana

    APP
    Sap
    100101102103104105106
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-0488CRITICAL9.9PL ✓same product

SAP CRM / S/4HANA Scripting Editor — nieautoryzowane wykonanie SQL

CVE-2022-22531HIGH8.1same product

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does ...

CVE-2021-38176HIGH8.8same product

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call N...

CVE-2026-27679MEDIUM6.5same product

Z powodu braku kontroli autoryzacji w usłudze OData frontendowej SAP S/4HANA (Manage Reference Structures), at...

CVE-2026-34264MEDIUM6.5same product

W trakcie kontroli autoryzacji w SAP Human Capital Management dla SAP S/4HANA system zwraca konkretne komunika...