A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.
References
| Link | Resource |
|---|---|
| https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022 | Vendor Advisory |
| https://launchpad.support.sap.com/#/notes/3128473 | Permissions Required |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-09 23:15
Updated : 2022-02-16 17:53
NVD link : CVE-2022-22545
Mitre link : CVE-2022-22545
JSON object : View
Products Affected
sap
- netweaver_abap
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
