CVE-2022-22545
Published Feb 9, 2022
Last updated 2 years ago
Overview
- Description
- A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.
- Source
- cna@sap.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.9
- Impact score
- 3.6
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- cna@sap.com
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sap:netweaver_abap:700:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0DA7CC6-A0F6-4839-965D-C60F691496AD" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:701:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6497854E-9C7B-4DAF-ADC6-F26523BB7D47" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:702:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFC58754-3A9D-4320-AB4F-385FB72608E7" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:710:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFE9B3CD-097D-4B66-8070-A46170736A0F" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:711:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0AD9BF3E-56CB-4387-AE46-6BCBCE2F5DE7" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:730:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D46B6A9-C9F3-4270-AA6D-9988D6D4E608" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:731:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B8A73A5-4526-40E1-A540-0A6C3F93DA05" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:740:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09A38B6E-03DC-4086-A307-542B35814E0E" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:750:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4651257F-7BFC-41AE-8E37-8C96F822CE58" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:751:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EECB438D-D5CD-4483-934F-4C814A725A35" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:752:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14A1CD95-14E1-438A-92FB-A0E47A88C59F" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:753:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4148303B-133A-4FD2-B546-DD86C5D0E7C1" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:754:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E51EF6BC-4C1C-4F1B-9873-D571BE3788F5" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:755:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "424A3D68-0825-4A2C-BEB1-DC9A212A5E42" }, { "criteria": "cpe:2.3:a:sap:netweaver_abap:756:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F4A410E-6276-4DD2-8C84-8B7DD06AD8FD" } ], "operator": "OR" } ] } ]