CVE-2022-39801 is a high-severity vulnerability in SAP GRC Access Control's Emergency Access Management, allowing an authenticated attacker to regain access to a closed Firefighter session. This attack, launched from within the firewall, has a CVSS score of 7.5 (High) due to its potential for complete application compromise and administrative session takeover. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12CPE matchmatch criteria | cpe:2.3:a:sap:access_control:12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.