← Back

CVE-2022-27668

nvd nist
Published: Jun 14, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

Affected (11)

4 products
Netweaver As Abap
Netweaver As Abap Krnl64nuc
Netweaver As Abap Krnl64uc
Router
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version kernel_7.49
Version kernel_7.77
Version kernel_7.81
Version kernel_7.85
Version kernel_7.86
Version kernel_7.87
Version kernel_7.88
Version 7.49
Version 7.49
Sap
Version 7.22
Version 7.53

References (8)

Source: cna@sap.com
ExploitMailing ListThird Party Advisory
Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.