CVE-2022-22543

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service attack. This allows an unauthorized remote user to provoke a breakdown of the SAP Web Dispatcher or Kernel work process. The crashed process can be restarted immediately, other processes are not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
sapCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
sapnetweaver_abap
7.22
sapnetweaver_abap
7.22ext:ext
sapnetweaver_abap
7.49
sapnetweaver_abap
7.53
sapnetweaver_abap
7.77
sapnetweaver_abap
7.81
sapnetweaver_abap
7.85
sapnetweaver_abap
7.86
sapnetweaver_abap
7.87
sapnetweaver_abap
8.04
sapnetweaver_as_abap
7.22
sapnetweaver_as_abap
7.22ext:ext
sapnetweaver_as_abap
7.49
sapnetweaver_as_abap
7.53
sapnetweaver_as_abap
7.77
sapnetweaver_as_abap
7.81
sapnetweaver_as_abap
7.85
sapnetweaver_as_abap
7.86
sapnetweaver_as_abap
7.87
sapnetweaver_as_abap
8.04
𝑥
= Vulnerable software versions