Information Disclosure in SAP NetWeaver and ABAP Platform by SAP
CVE-2022-29612
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 June 2022
Summary
SAP NetWeaver and ABAP Platform, along with SAP Host Agent, have a vulnerability that allows authenticated users to exploit the sapcontrol web functionality's startservice feature. This exploitation enables malicious users to access sensitive system information, such as system numbers and physical addresses, which would typically be restricted. Although the impact on the application's confidentiality is limited, it poses a risk of divulging technical information that could be leveraged in further attacks.
Affected Version(s)
SAP NetWeaver, ABAP Platform and SAP Host Agent KERNEL 7.22
SAP NetWeaver, ABAP Platform and SAP Host Agent 7.49
SAP NetWeaver, ABAP Platform and SAP Host Agent 7.53
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved