First published: Tue Jun 14 2022(Updated: )
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Developer Studio | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-29615 is considered low as it primarily affects confidentiality and integrity.
To fix CVE-2022-29615, upgrade to a version of SAP NetWeaver Developer Studio that does not contain the vulnerable log4j version.
CVE-2022-29615 could potentially lead to issues affecting the confidentiality and integrity of data processed by version 7.50.
CVE-2022-29615 affects SAP NetWeaver Developer Studio version 7.50 that uses log4j version 1.x.
Currently, the best approach for CVE-2022-29615 is to upgrade as no specific workaround is recommended.