PT-2022-15510 · Sap · Sap Netweaver As Abap

Published

2022-02-09

·

Updated

2022-10-05

·

CVE-2022-22540

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP (Workplace Server) versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787
Description The issue allows an attacker to execute crafted database queries, potentially exposing the backend database. Successful attacks could result in the disclosure of a table of contents from the system, although no modification is possible.
Recommendations For versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, consider restricting access to the database query functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-22540

Affected Products

Sap Netweaver As Abap