4.9

CVE-2022-22545

A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.

Data is provided by the National Vulnerability Database (NVD)
SAPNetweaver Abap Version700
SAPNetweaver Abap Version701
SAPNetweaver Abap Version702
SAPNetweaver Abap Version710
SAPNetweaver Abap Version711
SAPNetweaver Abap Version730
SAPNetweaver Abap Version731
SAPNetweaver Abap Version740
SAPNetweaver Abap Version750
SAPNetweaver Abap Version751
SAPNetweaver Abap Version752
SAPNetweaver Abap Version753
SAPNetweaver Abap Version754
SAPNetweaver Abap Version755
SAPNetweaver Abap Version756
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.555
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.