VYPR
Unrated severityNVD Advisory· Published Jun 14, 2022· Updated Aug 3, 2024

CVE-2022-27668

CVE-2022-27668

Description

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • SAP/SAProuterllm-fuzzy
    Range: SAP_ROUTER 7.53, 7.22
  • SAP/Netweaverllm-fuzzy
    Range: KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49
  • SAP SE/SAP NetWeaver and ABAP Platformv5
    Range: KERNEL 7.49

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.