« Volver al listado

CVE-2022-28772

Estado: ModificadaAlta (7.5)—

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28772",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver (Internet Communication Manager)",
          "versions": [
            {
              "status": "affected",
              "version": "KRNL64NUC 7.22"
            },
            {
              "status": "affected",
              "version": "7.22EXT"
            },
            {
              "status": "affected",
              "version": "7.49"
            },
            {
              "status": "affected",
              "version": "KRNL64UC 7.22"
            },
            {
              "status": "affected",
              "version": "7.53"
            },
            {
              "status": "affected",
              "version": "KERNEL 7.22"
            },
            {
              "status": "affected",
              "version": "7.77"
            },
            {
              "status": "affected",
              "version": "7.81"
            },
            {
              "status": "affected",
              "version": "7.85"
            },
            {
              "status": "affected",
              "version": "7.86"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP Web Dispatcher",
          "versions": [
            {
              "status": "affected",
              "version": "7.53"
            },
            {
              "status": "affected",
              "version": "7.77"
            },
            {
              "status": "affected",
              "version": "7.81"
            },
            {
              "status": "affected",
              "version": "7.85"
            },
            {
              "status": "affected",
              "version": "7.86"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-12T17:15:10.833",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/3111311",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3111311",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service."
    },
    {
      "lang": "es",
      "value": "Mediante valores de entrada demasiado largos, un atacante puede forzar la sobreescritura de la pila interna del programa en SAP Web Dispatcher - versiones 7.53, 7.77, 7.81, 7.85, 7.86, o Internet Communication Manager - versiones KRNL64NUC 7. 22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, lo que hace que estos programas no estén disponibles, conllevando a una denegación de servicio"
    }
  ],
  "lastModified": "2026-06-17T04:38:59.857",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.22ext:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71AFBCEC-649C-4389-85C2-6C245290E91A"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.49:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7245DC9-CB62-477A-86B3-41CBBB878F3B"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77CA44BC-8650-4A20-A359-0FE568E1B345"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.77:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95D831B3-1B5B-441F-8429-B6EC7161A7B5"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.81:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D232796-B486-4C58-AD93-46D5948F1586"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.85:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93AA0006-CEEC-4037-B1FC-3C4A7E0D1905"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.86:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C269F298-5AB8-4AA1-911A-403F5EA62DEE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:kernel_7.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87AABA4D-7683-47B4-BAF7-22AA42E074D4"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:krnl64nuc_7.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D28A3C2-D601-405F-A17C-6A6EBE43DF31"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:krnl64uc_7.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA038239-63B2-4C31-8E74-EE053548621D"
            },
            {
              "criteria": "cpe:2.3:a:sap:web_dispatcher:7.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47D4D542-2EC2-490B-B4E9-3E7BB8D59B77"
            },
            {
              "criteria": "cpe:2.3:a:sap:web_dispatcher:7.77:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E33D9481-3CF6-4AA3-B115-7903AC6DAE25"
            },
            {
              "criteria": "cpe:2.3:a:sap:web_dispatcher:7.81:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49FF2A5B-E5F0-4991-9AA3-7CB3B8C62941"
            },
            {
              "criteria": "cpe:2.3:a:sap:web_dispatcher:7.85:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F74EE4D5-E968-4851-89E6-4152F64930F2"
            },
            {
              "criteria": "cpe:2.3:a:sap:web_dispatcher:7.86:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "327A87AD-6635-4511-8505-F4418CD9D49C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}