CVE-2022-41215: Medium severity SAP NetWeaver Application Server ABAP vulnerability
Published Nov 8, 2022
·Updated
SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
Affected Software
5 affected components
SAP NetWeaver Application Server ABAP=700
SAP NetWeaver Application Server ABAP=731
SAP NetWeaver Application Server ABAP=740
SAP NetWeaver Application Server ABAP=750
SAP NetWeaver Application Server ABAP=789
Event History
Nov 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-41215.
2
What is the severity of vulnerability CVE-2022-41215?
The severity of vulnerability CVE-2022-41215 is medium.
3
How can an attacker exploit vulnerability CVE-2022-41215?
An unauthenticated attacker can exploit vulnerability CVE-2022-41215 by redirecting users to a malicious website.
4
Which SAP software versions are affected by vulnerability CVE-2022-41215?
Vulnerability CVE-2022-41215 affects SAP NetWeaver Application Server ABAP versions 700, 731, 740, 750, and 789.
5
What can be the impact of vulnerability CVE-2022-41215?
Vulnerability CVE-2022-41215 can lead to users being tricked into disclosing personal information.