CVE-2022-27668
Last modified
CVE-2022-27668 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver As Abap | kernel_7.49 |
| Sap | Netweaver As Abap | kernel_7.77 |
| Sap | Netweaver As Abap | kernel_7.81 |
| Sap | Netweaver As Abap | kernel_7.85 |
| Sap | Netweaver As Abap | kernel_7.86 |
| Sap | Netweaver As Abap | kernel_7.87 |
| Sap | Netweaver As Abap | kernel_7.88 |
| Sap | Netweaver As Abap Krnl64nuc | 7.49 |
| Sap | Netweaver As Abap Krnl64uc | 7.49 |
| Sap | Router | 7.22 |
| Sap | Router | 7.53 |
References
- http://packetstormsecurity.com/files/168406/SAP-SAProuter-Improper-Access-Control.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Sep/17Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3158375Permissions Required, Vendor Advisory
- http://packetstormsecurity.com/files/168406/SAP-SAProuter-Improper-Access-Control.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Sep/17Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3158375Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27668?
How severe is CVE-2022-27668?
How do I fix CVE-2022-27668?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-27661Operation restriction bypass vulnerability in Workflow of Cy…4.3
- CVE-2022-27662On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x ve…4.8
- CVE-2022-27664In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, at…7.5
- CVE-2022-27665Reflected XSS (via AngularJS sandbox escape expressions) exi…6.1
- CVE-2022-27666A heap buffer overflow flaw was found in IPsec ESP transform…7.8
- CVE-2022-27667Under certain conditions, SAP BusinessObjects Business Intel…7.5
- CVE-2022-27669An unauthenticated user can use functions of XML Data Archiv…7.5
- CVE-2022-2767A vulnerability classified as problematic has been found in …6.1
- CVE-2022-27670SAP SQL Anywhere - version 17.0, allows an authenticated att…6.5
- CVE-2022-27671A CSRF token visible in the URL may possibly lead to informa…6.5
- CVE-2022-27672When SMT is enabled, certain AMD processors may speculativel…4.7
- CVE-2022-27673Insufficient access controls in the AMD Link Android app may…7.5
Are you affected by CVE-2022-27668?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
