Логотип exploitDog
bind:CVE-2022-35291
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-35291

Количество 3

Количество 3

nvd логотип

CVE-2022-35291

больше 3 лет назад

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-mj46-hjj8-xr5c

больше 3 лет назад

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2022-04760

больше 3 лет назад

Уязвимость реализации модулей Time Off, Time Sheet, EC Workflow и Benefits мобильной платформы управления персоналом SAP SuccessFactors Mobile операционных систем Android и iOS, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-35291

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mj46-hjj8-xr5c

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-04760

Уязвимость реализации модулей Time Off, Time Sheet, EC Workflow и Benefits мобильной платформы управления персоналом SAP SuccessFactors Mobile операционных систем Android и iOS, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу