Vulnerability Description
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sapcar | 7.22 |
Related Weaknesses (CWE)
References
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3111110Permissions RequiredVendor Advisory
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3111110Permissions RequiredVendor Advisory
FAQ
What is CVE-2022-26100?
CVE-2022-26100 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.
How severe is CVE-2022-26100?
CVE-2022-26100 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-26100?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Sapcar.