CVE-2022-29615

LOW

SAP Netweaver Developer Studio - Insecure Deserialization

Title source: rule

Description

SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.

Scores

CVSS v3 3.4
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-502
Status published

Affected Products (1)

sap/netweaver_developer_studio

Timeline

Published Jun 14, 2022
Tracked Since Feb 18, 2026