← Back

CVE-2022-29612

nvd nist
Published: Jun 14, 2022Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.

Affected (18)

2 products
Host Agent
Netweaver Abap
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.22
Sap
Version kernel_7.22
Version kernel_7.49
Version kernel_7.53
Version kernel_7.77
Version kernel_7.81
Version kernel_7.85
Version kernel_7.86
Version kernel_7.87
Version kernel_7.88
Version kernel_8.04
Version krnl64nuc_7.22
Version krnl64nuc_7.22ext
Version krnl64uc_7.22
Version krnl64uc_7.22ext
Version krnl64uc_7.49
Version krnl64uc_7.53
Version krnl64uc_8.04

References (4)

Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.