High
CVE-2022-41264
SAP BASIS could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unrestricted scope of the RFC function module. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Code Execution
SAP
Current SAP customers should refer to SAP note for patch information, available from the SAP Website (login required).