Code Injection Vulnerability in SAP NetWeaver
CVE-2022-22534

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 February 2022

Summary

SAP NetWeaver is vulnerable due to inadequate encoding of user input, allowing for potential code injection by unauthenticated attackers. This exploit can lead to unauthorized access to sensitive information, such as user IDs and passwords, especially through exposed network endpoints. Successful exploitation may compromise the confidentiality of applications leveraging SAP NetWeaver, thereby posing a significant risk to user data integrity and privacy.

Affected Version(s)

SAP NetWeaver (ABAP and Java application Servers) 700

SAP NetWeaver (ABAP and Java application Servers) 701

SAP NetWeaver (ABAP and Java application Servers) 702

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.