CVE-2022-1248
SAP Information System POST Request add_admin.php improper authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web application with a simple POST request. Exploit details were disclosed.
Se ha encontrado una vulnerabilidad en SAP Information System versión 1.0, que ha sido calificada como crítica. Este problema afecta al archivo /SAP_Information_System/controllers/add_admin.php. Un atacante no autenticado es capaz de crear una nueva cuenta de administrador para la aplicación web con una simple petición POST. Han sido divulgados los detalles de la explotación
SAP Information System version 1.0.0 suffers from an improper authentication vulnerability that allows a malicious user to create an administrative account without needing to authenticate. The POST request is sent to the /SAP_Information_System/controllers/add_admin.php endpoint. The problem occurs due to lack of session verification in the request.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-06 CVE Reserved
- 2022-04-06 CVE Published
- 2022-04-07 First Exploit
- 2024-08-02 CVE Updated
- 2024-12-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/166609 | 2022-04-07 | |
http://packetstormsecurity.com/files/166609/SAP-Information-System-1.0.0-Missing-Authorization.html | 2024-08-02 | |
https://vuldb.com/?id.196550 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Information System Project Search vendor "Sap Information System Project" | Sap Information System Search vendor "Sap Information System Project" for product "Sap Information System" | 1.0 Search vendor "Sap Information System Project" for product "Sap Information System" and version "1.0" | - |
Affected
|