CVE Database
/

CVE-2022-28772

Back to search

CVE-2022-28772

Published: Apr 12, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

VendorProductVersions

SAP SE

SAP NetWeaver (Internet Communication Manager)

affected
KRNL64NUC 7.22
affected
7.22EXT
affected
7.49
affected
KRNL64UC 7.22
affected
7.53

+5 more versions

SAP SE

SAP Web Dispatcher

affected
7.53
affected
7.77
affected
7.81
affected
7.85
affected
7.86

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now