CVE-2022-28773: High severity SAP NetWeaver vulnerability
Published Apr 12, 2022
·Updated
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.
Affected Software
15 affected components
SAP NetWeaver=7.22ext
SAP NetWeaver=7.49
SAP NetWeaver=7.53
SAP NetWeaver=7.77
SAP NetWeaver=7.81
SAP NetWeaver=7.85
SAP NetWeaver=7.86
SAP NetWeaver=kernel_7.22
SAP NetWeaver=krnl64nuc_7.22
SAP NetWeaver=krnl64uc_7.22
SAP Web Dispatcher=7.53
SAP Web Dispatcher=7.77
SAP Web Dispatcher=7.81
SAP Web Dispatcher=7.85
SAP Web Dispatcher=7.86
Event History
Apr 12, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-28773.
2
What is the severity of CVE-2022-28773?
The severity of CVE-2022-28773 is high with a severity value of 7.5.
3
Which software versions are affected by CVE-2022-28773?
The following SAP NetWeaver and SAP Web Dispatcher versions are affected: 7.22ext, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, kernel_7.22, krnl64nuc_7.22, krnl64uc_7.22, 7.53, 7.77, 7.81, 7.85, and 7.86.
4
How can CVE-2022-28773 impact an application?
CVE-2022-28773 can cause the application to crash, leading to denial of service, but it can be automatically restarted.
5
How can I fix CVE-2022-28773?
To fix CVE-2022-28773, apply the necessary patches provided by SAP and follow their recommended mitigation measures.