CVE-2022-22540
Summary
| CVE | CVE-2022-22540 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 23:15:00 UTC |
| Updated | 2022-10-05 14:16:00 UTC |
| Description | SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Application Server Abap | 700 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 701 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 702 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 731 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 740 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 750 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 751 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 752 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 753 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 754 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 755 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 756 | All | All | All |
| Application | Sap | Netweaver Application Server Abap | 787 | All | All | All |
| Application | Sap | Netweaver As Abap | 700 | All | All | All |
| Application | Sap | Netweaver As Abap | 701 | All | All | All |
| Application | Sap | Netweaver As Abap | 702 | All | All | All |
| Application | Sap | Netweaver As Abap | 731 | All | All | All |
| Application | Sap | Netweaver As Abap | 740 | All | All | All |
| Application | Sap | Netweaver As Abap | 750 | All | All | All |
| Application | Sap | Netweaver As Abap | 751 | All | All | All |
| Application | Sap | Netweaver As Abap | 752 | All | All | All |
| Application | Sap | Netweaver As Abap | 753 | All | All | All |
| Application | Sap | Netweaver As Abap | 754 | All | All | All |
| Application | Sap | Netweaver As Abap | 755 | All | All | All |
| Application | Sap | Netweaver As Abap | 756 | All | All | All |
| Application | Sap | Netweaver As Abap | 787 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| SAP Security Patch Day - February 2022 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | |
| Access Denied | MISC | www.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87484 SAP NetWeaver AS ABAP SQL Injection Vulnerability (3140587)