Back to overview

CVE-2022-41272

CRITICAL
9.9
CVSS 3.1
Description
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application.

Metadata

CVE ID
CVE-2022-41272
State
PUBLISHED
Assigner
sap
Reserved
2022-09-21 16:20 UTC
Published
2022-12-13 03:05 UTC
Last updated
2025-04-21 15:32 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
SAP / NetWeaver Process Integration
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
SAP NetWeaver Process Integration 7.50
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306 Missing Authentication for Critical Function
CWE-862 cna CWE-862 Missing Authorization
CWE-89 cna CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Back to overview