Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-27668

Опубликовано: 14 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_as_abap:kernel_7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.77:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.81:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.85:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.86:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.87:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:kernel_7.88:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap_krnl64nuc:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap_krnl64uc:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:router:7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:router:7.53:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02529
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

CVSS3: 8.6
fstec
почти 4 года назад

Уязвимость файла saprouttab программных интеграционных платформ SAP NetWeaver и SAP ABAP, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 85%
0.02529
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863