CVE-2022-29612
Last modified
CVE-2022-29612 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Host Agent | 7.22 |
| Sap | Netweaver Abap | kernel_7.22 |
| Sap | Netweaver Abap | kernel_7.49 |
| Sap | Netweaver Abap | kernel_7.53 |
| Sap | Netweaver Abap | kernel_7.77 |
| Sap | Netweaver Abap | kernel_7.81 |
| Sap | Netweaver Abap | kernel_7.85 |
| Sap | Netweaver Abap | kernel_7.86 |
| Sap | Netweaver Abap | kernel_7.87 |
| Sap | Netweaver Abap | kernel_7.88 |
| Sap | Netweaver Abap | kernel_8.04 |
| Sap | Netweaver Abap | krnl64nuc_7.22 |
| Sap | Netweaver Abap | krnl64nuc_7.22ext |
| Sap | Netweaver Abap | krnl64uc_7.22 |
| Sap | Netweaver Abap | krnl64uc_7.22ext |
| Sap | Netweaver Abap | krnl64uc_7.49 |
| Sap | Netweaver Abap | krnl64uc_7.53 |
| Sap | Netweaver Abap | krnl64uc_8.04 |
References
- https://launchpad.support.sap.com/#/notes/3194674Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3194674Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29612?
How severe is CVE-2022-29612?
How do I fix CVE-2022-29612?
Are you affected by CVE-2022-29612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
