← Vulnerability feed

Vulnerability record · CVE-2022-31589 · published 14 June 2022

CVE-2022-31589: Sap erp financial accounting incorrect authorization vulnerability

Sap · Erp Financial Accounting

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

6.5 CVSS 3.1 Medium EPSS 0.66% · top 50.6% CWE-863 · Incorrect authorization
6.5CVSS 3.1 base score, v2 4.0
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31589 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-0488Sap netweaver application server abap missing authorization vulnerabilityAn authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…EPSS 0.51%8.8CVE-2021-38176Sap landscape transformation sql injection vulnerabilityDue to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution…EPSS 1.3%8.1CVE-2022-22530Sap s\/4hana vulnerabilityThe F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…EPSS 0.94%8.1CVE-2022-22531Sap s\/4hana vulnerabilityThe F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…EPSS 0.85%6.5CVE-2023-24524Sap s\/4hana missing authorization vulnerabilitySAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalatio…EPSS 0.52%6.5CVE-2022-22542Sap s\/4hana information exposure vulnerabilityS/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…EPSS 0.90%6.1CVE-2023-40306Sap s\/4hana open redirect vulnerabilitySAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…EPSS 0.37%6.1CVE-2020-6184Sap netweaver cross-site scripting vulnerabilityUnder certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53,…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2022-31589), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.