CVE-2022-31590

HIGH

SAP PowerDesigner Proxy 16.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3197005

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
sap/powerdesigner_proxy 16.7
Published Jun 14, 2022
Tracked Since Feb 18, 2026