CVE-2022-22540 PUBLISHED CVSS 7.5 HIGH

SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.

EPSS 0.37% · 58.3th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.37%
58.3th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_abap787, 700, 701
SAP SESAP NetWeaver AS ABAP (Workplace Server)700, 701, 702

Timeline

References

Open in Interactive Console →