Lucene search

K
cvelistSapCVELIST:CVE-2022-22532
HistoryFeb 09, 2022 - 10:05 p.m.

CVE-2022-22532

2022-02-0922:05:19
CWE-444
sap
www.cve.org
2

9.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%

In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be executed and hence execute functions that could be impersonating the victim or even steal the victim’s logon session.

CNA Affected

[
  {
    "product": "SAP NetWeaver Application Server Java",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "KRNL64NUC 7.22"
      },
      {
        "status": "affected",
        "version": "7.22EXT"
      },
      {
        "status": "affected",
        "version": "7.49"
      },
      {
        "status": "affected",
        "version": "KRNL64UC"
      },
      {
        "status": "affected",
        "version": "7.22"
      },
      {
        "status": "affected",
        "version": "7.53"
      },
      {
        "status": "affected",
        "version": "KERNEL 7.22"
      }
    ]
  }
]

9.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%

Related for CVELIST:CVE-2022-22532