CVE-2022-28772
Published: Apr 12, 2022
Modified: Aug 3, 2024
Description
By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP NetWeaver (Internet Communication Manager) | affected KRNL64NUC 7.22affected 7.22EXTaffected 7.49affected KRNL64UC 7.22affected 7.53+5 more versions |
SAP SE | SAP Web Dispatcher | affected 7.53affected 7.77affected 7.81affected 7.85affected 7.86 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now