CVE-2022-22528

HIGH

SAP ASE <16.0 - Privilege Escalation

Title source: llm

Description

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on the local system. The issue is with the ASE installer and does not impact other ASE binaries.

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 30.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

sap/adaptive_server_enterprise

Timeline

Published Feb 09, 2022
Tracked Since Feb 18, 2026