Back to search
CVE-2022-22534
Published: Feb 9, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP NetWeaver (ABAP and Java application Servers) | affected 700affected 701affected 702affected 731affected 740+7 more versions |
References
https://launchpad.support.sap.com/#/notes/3124994
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now