CVE-2022-41207: SAP Biller Direct

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.

Affected products

  • SAP Biller Direct: version 635 only; version 750 only

Published 2022-11-08. Last modified 2026-06-17.