SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22534

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password.

MEDIUM 6.1EPSS 0.83%

Does this matter?

Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.

Description

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.83% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
sap/netweaver
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.