CVE-2022-27668
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.
- Affected products
- Abap Platform, Kernel, Krnl64Uc, Sap Netweaver, Saprouter
- Sap Netweaver As Abap
- = kernel_7.49, kernel_7.77, kernel_7.81, kernel_7.85, kernel_7.86, kernel_7.87, kernel_7.88
- Sap Netweaver As Abap krnl64nuc
- = 7.49
- Sap Netweaver As Abap krnl64uc
- = 7.49
- Sap Router
- = 7.22, 7.53
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2022-06-14
CVE-2022-27668 at NVD
1 known exploit for CVE-2022-27668
Proof-of-concept code and exploit modules indexed by Sploitus