CVE Database
/

CVE-2022-22528

Back to search

CVE-2022-22528

Published: Feb 9, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on the local system. The issue is with the ASE installer and does not impact other ASE binaries.

VendorProductVersions

SAP SE

SAP Adaptive Server Enterprise

affected
16.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now