CVE-2022-29615
LOWSAP Netweaver Developer Studio - Insecure Deserialization
Title source: ruleDescription
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.
Scores
CVSS v3
3.4
EPSS
0.0009
EPSS Percentile
24.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-502
Status
published
Affected Products (1)
sap/netweaver_developer_studio
Timeline
Published
Jun 14, 2022
Tracked Since
Feb 18, 2026