CVE-2022-41212
MEDIUMSAP NetWeaver Application Server ABAP/ABAP Platform - Info Disclosure
Title source: llmDescription
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3256571
Scores
CVSS v3
4.9
EPSS
0.0048
EPSS Percentile
65.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (6)
sap/netweaver_application_server_abap
700
sap/netweaver_application_server_abap
731
sap/netweaver_application_server_abap
740
sap/netweaver_application_server_abap
750
sap/netweaver_application_server_abap
789
sap/netweaver_application_server_abap
804
Published
Nov 08, 2022
Tracked Since
Feb 18, 2026