CVE-2022-22540: SQL Injection
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22540?
CVE-2022-22540 is a vulnerability in SAP NetWeaver AS ABAP (Workplace Server) that allows an attacker to execute crafted database queries and potentially expose the backend database.
Which versions of SAP NetWeaver AS ABAP are affected by CVE-2022-22540?
Versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, and 787 of SAP NetWeaver AS ABAP are affected by CVE-2022-22540.
What is the severity of CVE-2022-22540?
CVE-2022-22540 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2022-22540?
An attacker can exploit CVE-2022-22540 by executing crafted database queries.
Are there any references available for CVE-2022-22540?
Yes, you can find more information about CVE-2022-22540 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/3140587) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).