CVE-2022-29615

LOW

SAP NetWeaver Developer Studio 7.50 - Deserialization of Untrusted Data

Title source: llm
STIX 2.1

Description

SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3202846

Scores

CVSS v3 3.4
EPSS 0.0009
EPSS Percentile 24.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-502
Status published
Products (1)
sap/netweaver_developer_studio 7.50
Published Jun 14, 2022
Tracked Since Feb 18, 2026