CVE-2022-29611

HIGH

SAP NetWeaver Application Server ABAP and ABAP Platform - Missing Authorization

Title source: llm
STIX 2.1

Description

SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3165801

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (17)
sap/netweaver_application_server_abap 700
sap/netweaver_application_server_abap 701
sap/netweaver_application_server_abap 702
sap/netweaver_application_server_abap 710
sap/netweaver_application_server_abap 711
sap/netweaver_application_server_abap 730
sap/netweaver_application_server_abap 731
sap/netweaver_application_server_abap 740
sap/netweaver_application_server_abap 750
sap/netweaver_application_server_abap 751
... and 7 more
Published May 11, 2022
Tracked Since Feb 18, 2026