CVE-2022-22545: Infoleak
A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22545.
What is the severity of CVE-2022-22545?
The severity of CVE-2022-22545 is medium with a severity value of 4.9.
Which software versions are affected by CVE-2022-22545?
SAP NetWeaver Application Server ABAP and ABAP Platform versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, and 756 are affected by CVE-2022-22545.
How can a high privileged user exploit CVE-2022-22545?
A high privileged user can exploit CVE-2022-22545 by accessing transaction SM59 and reading connection details stored with the destination for HTTP calls.
Are there any fixes available for CVE-2022-22545?
Yes, SAP has provided fixes for CVE-2022-22545. Refer to the SAP notes for more information.