Information Disclosure in SAP NetWeaver and ABAP Platform by SAP
CVE-2022-29612

4.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 June 2022

Summary

SAP NetWeaver and ABAP Platform, along with SAP Host Agent, have a vulnerability that allows authenticated users to exploit the sapcontrol web functionality's startservice feature. This exploitation enables malicious users to access sensitive system information, such as system numbers and physical addresses, which would typically be restricted. Although the impact on the application's confidentiality is limited, it poses a risk of divulging technical information that could be leveraged in further attacks.

Affected Version(s)

SAP NetWeaver, ABAP Platform and SAP Host Agent KERNEL 7.22

SAP NetWeaver, ABAP Platform and SAP Host Agent 7.49

SAP NetWeaver, ABAP Platform and SAP Host Agent 7.53

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.