Code Injection Vulnerability in SAP NetWeaver
CVE-2022-22534
6.1MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 February 2022
Summary
SAP NetWeaver is vulnerable due to inadequate encoding of user input, allowing for potential code injection by unauthenticated attackers. This exploit can lead to unauthorized access to sensitive information, such as user IDs and passwords, especially through exposed network endpoints. Successful exploitation may compromise the confidentiality of applications leveraging SAP NetWeaver, thereby posing a significant risk to user data integrity and privacy.
Affected Version(s)
SAP NetWeaver (ABAP and Java application Servers) 700
SAP NetWeaver (ABAP and Java application Servers) 701
SAP NetWeaver (ABAP and Java application Servers) 702
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved