CVE-2022-41212: Path Traversal
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41212?
CVE-2022-41212 is a vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform that allows an attacker with high-level privileges to read a restricted file using a remote enabled function.
How severe is CVE-2022-41212?
CVE-2022-41212 has a severity rating of 4.9 (medium).
Which versions of SAP NetWeaver Application Server ABAP are affected by CVE-2022-41212?
Versions 700, 731, 740, 750, 789, and 804 of SAP NetWeaver Application Server ABAP are affected by CVE-2022-41212.
How can an attacker exploit CVE-2022-41212?
An attacker can exploit CVE-2022-41212 by using a remote enabled function to read a restricted file.
Are there any references for CVE-2022-41212?
Yes, you can find references for CVE-2022-41212 at the following links: [https://launchpad.support.sap.com/#/notes/3256571](https://launchpad.support.sap.com/#/notes/3256571) and [https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).