7.5
CVSSv3

CVE-2022-28772

Published: 12/04/2022 Updated: 20/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver 7.22ext

sap netweaver 7.49

sap netweaver 7.53

sap netweaver 7.77

sap netweaver 7.81

sap netweaver 7.85

sap netweaver 7.86

sap netweaver kernel_7.22

sap netweaver krnl64nuc_7.22

sap netweaver krnl64uc_7.22

sap web dispatcher 7.53

sap web dispatcher 7.77

sap web dispatcher 7.81

sap web dispatcher 7.85

sap web dispatcher 7.86