CVE Vulnerabilities

CVE-2022-29612

Server-Side Request Forgery (SSRF)

Published: Jun 14, 2022 | Modified: Oct 06, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Host_agent Sap 7.22 (including) 7.22 (including)
Netweaver_abap Sap kernel_7.22 (including) kernel_7.22 (including)
Netweaver_abap Sap kernel_7.49 (including) kernel_7.49 (including)
Netweaver_abap Sap kernel_7.53 (including) kernel_7.53 (including)
Netweaver_abap Sap kernel_7.77 (including) kernel_7.77 (including)
Netweaver_abap Sap kernel_7.81 (including) kernel_7.81 (including)
Netweaver_abap Sap kernel_7.85 (including) kernel_7.85 (including)
Netweaver_abap Sap kernel_7.86 (including) kernel_7.86 (including)
Netweaver_abap Sap kernel_7.87 (including) kernel_7.87 (including)
Netweaver_abap Sap kernel_7.88 (including) kernel_7.88 (including)
Netweaver_abap Sap kernel_8.04 (including) kernel_8.04 (including)
Netweaver_abap Sap krnl64nuc_7.22 (including) krnl64nuc_7.22 (including)
Netweaver_abap Sap krnl64nuc_7.22ext (including) krnl64nuc_7.22ext (including)
Netweaver_abap Sap krnl64uc_7.22 (including) krnl64uc_7.22 (including)
Netweaver_abap Sap krnl64uc_7.22ext (including) krnl64uc_7.22ext (including)
Netweaver_abap Sap krnl64uc_7.49 (including) krnl64uc_7.49 (including)
Netweaver_abap Sap krnl64uc_7.53 (including) krnl64uc_7.53 (including)
Netweaver_abap Sap krnl64uc_8.04 (including) krnl64uc_8.04 (including)

References