CVE-2022-41214
HIGHSAP NetWeaver Application Server ABAP/ABAP Platform - Privilege Esc...
Title source: llmDescription
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3256571
Scores
CVSS v3
8.7
EPSS
0.0042
EPSS Percentile
62.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (6)
sap/netweaver_application_server_abap
700
sap/netweaver_application_server_abap
731
sap/netweaver_application_server_abap
740
sap/netweaver_application_server_abap
750
sap/netweaver_application_server_abap
789
sap/netweaver_application_server_abap
804
Published
Nov 08, 2022
Tracked Since
Feb 18, 2026