Denial of Service Vulnerability in SAP Web Dispatcher and SAP Internet Communication Manager
CVE-2022-28773
7.5HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 April 2022
Summary
An uncontrolled recursion issue has been identified in SAP Web Dispatcher and SAP Internet Communication Manager. This vulnerability may result in the applications crashing, which unexpectedly leads to a denial of service scenario. Fortunately, the systems can self-restart automatically, but this interruption may affect the availability of services reliant on these applications.
Affected Version(s)
SAP NetWeaver (Internet Communication Manager) KRNL64NUC 7.22
SAP NetWeaver (Internet Communication Manager) 7.22EXT
SAP NetWeaver (Internet Communication Manager) 7.49
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved