4.3
CVE-2022-29612
- EPSS 0.15%
- Veröffentlicht 14.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:25
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Host Agent Version7.22
SAP ≫ Netweaver Abap Versionkernel_7.22
SAP ≫ Netweaver Abap Versionkernel_7.49
SAP ≫ Netweaver Abap Versionkernel_7.53
SAP ≫ Netweaver Abap Versionkernel_7.77
SAP ≫ Netweaver Abap Versionkernel_7.81
SAP ≫ Netweaver Abap Versionkernel_7.85
SAP ≫ Netweaver Abap Versionkernel_7.86
SAP ≫ Netweaver Abap Versionkernel_7.87
SAP ≫ Netweaver Abap Versionkernel_7.88
SAP ≫ Netweaver Abap Versionkernel_8.04
SAP ≫ Netweaver Abap Versionkrnl64nuc_7.22
SAP ≫ Netweaver Abap Versionkrnl64nuc_7.22ext
SAP ≫ Netweaver Abap Versionkrnl64uc_7.22
SAP ≫ Netweaver Abap Versionkrnl64uc_7.22ext
SAP ≫ Netweaver Abap Versionkrnl64uc_7.49
SAP ≫ Netweaver Abap Versionkrnl64uc_7.53
SAP ≫ Netweaver Abap Versionkrnl64uc_8.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.15% | 0.36 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.