CVE-2022-22543: High severity sap netweaver as abap vulnerability
SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service attack. This allows an unauthorized remote user to provoke a breakdown of the SAP Web Dispatcher or Kernel work process. The crashed process can be restarted immediately, other processes are not affected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22543?
CVE-2022-22543 is a vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows the execution of unauthorized actions.
What is the severity of CVE-2022-22543?
CVE-2022-22543 has a severity rating of high.
How does CVE-2022-22543 affect SAP NetWeaver ABAP?
CVE-2022-22543 affects SAP NetWeaver ABAP versions 7.22, 7.22ext, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, and 8.04.
Is there a fix available for CVE-2022-22543?
Yes, SAP has released a security note with instructions on how to fix CVE-2022-22543.
Where can I find more information about CVE-2022-22543?
More information about CVE-2022-22543 can be found in the SAP Security Note [link] and the SAP document [link].