Privilege Escalation in SAP Adaptive Server Enterprise on Windows
CVE-2022-22528

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 February 2022

Summary

A vulnerability exists in the SAP Adaptive Server Enterprise (ASE) version 16.0 installer for Windows, which adds an entry to the system PATH environment variable. This could potentially allow a Standard User to run malicious Windows binaries under specific circumstances, leading to privilege escalation on the local system. Notably, this issue is isolated to the ASE installer and does not affect other ASE binaries.

Affected Version(s)

SAP Adaptive Server Enterprise 16.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.