CVE-2022-41212

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:789:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:804:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-11-08 22:15

Updated : 2022-11-09 15:41


NVD link : CVE-2022-41212

Mitre link : CVE-2022-41212

CVE.ORG link : CVE-2022-41212


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')