CRITICAL · 9.8

CVE-2022-27668

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP...

Vulnerability Description

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SapNetweaver As Abapkernel_7.49
SapNetweaver As Abap Krnl64Nuc7.49
SapNetweaver As Abap Krnl64Uc7.49
SapRouter7.22

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-27668?

CVE-2022-27668 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP...

How severe is CVE-2022-27668?

CVE-2022-27668 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-27668?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver As Abap, Sap Netweaver As Abap Krnl64Nuc, Sap Netweaver As Abap Krnl64Uc, Sap Router.