Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-29612


SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.


Published

2022-06-14T17:15:08.230

Last Modified

2024-11-21T06:59:25.833

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap host_agent 7.22 Yes
Application sap netweaver_abap kernel_7.22 Yes
Application sap netweaver_abap kernel_7.49 Yes
Application sap netweaver_abap kernel_7.53 Yes
Application sap netweaver_abap kernel_7.77 Yes
Application sap netweaver_abap kernel_7.81 Yes
Application sap netweaver_abap kernel_7.85 Yes
Application sap netweaver_abap kernel_7.86 Yes
Application sap netweaver_abap kernel_7.87 Yes
Application sap netweaver_abap kernel_7.88 Yes
Application sap netweaver_abap kernel_8.04 Yes
Application sap netweaver_abap krnl64nuc_7.22 Yes
Application sap netweaver_abap krnl64nuc_7.22ext Yes
Application sap netweaver_abap krnl64uc_7.22 Yes
Application sap netweaver_abap krnl64uc_7.22ext Yes
Application sap netweaver_abap krnl64uc_7.49 Yes
Application sap netweaver_abap krnl64uc_7.53 Yes
Application sap netweaver_abap krnl64uc_8.04 Yes

References