Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22543


SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service attack. This allows an unauthorized remote user to provoke a breakdown of the SAP Web Dispatcher or Kernel work process. The crashed process can be restarted immediately, other processes are not affected.


Published

2022-02-09T23:15:18.913

Last Modified

2024-11-21T06:46:59.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_abap 7.22 Yes
Application sap netweaver_abap 7.22ext Yes
Application sap netweaver_abap 7.49 Yes
Application sap netweaver_abap 7.53 Yes
Application sap netweaver_abap 7.77 Yes
Application sap netweaver_abap 7.81 Yes
Application sap netweaver_abap 7.85 Yes
Application sap netweaver_abap 7.86 Yes
Application sap netweaver_abap 7.87 Yes
Application sap netweaver_abap 8.04 Yes
Application sap netweaver_abap krnl64nuc_7.22 Yes
Application sap netweaver_abap krnl64nuc_8.04 Yes
Application sap netweaver_as_abap 7.22 Yes
Application sap netweaver_as_abap 7.22ext Yes
Application sap netweaver_as_abap 7.49 Yes
Application sap netweaver_as_abap 7.53 Yes
Application sap netweaver_as_abap 7.77 Yes
Application sap netweaver_as_abap 7.81 Yes
Application sap netweaver_as_abap 7.85 Yes
Application sap netweaver_as_abap 7.86 Yes
Application sap netweaver_as_abap 7.87 Yes
Application sap netweaver_as_abap 8.04 Yes
Application sap netweaver_as_abap krnl64nuc_7.22 Yes
Application sap netweaver_as_abap krnl64nuc_8.04 Yes

References