PT-2022-15514 · Sap · Sap Netweaver Application Server Abap

Published

2022-02-09

·

Updated

2022-10-25

·

CVE-2022-22545

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP and ABAP Platform versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756
Description A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls.
Recommendations For versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, consider restricting access to transaction SM59 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-22545

Affected Products

Sap Netweaver Application Server Abap