// For flags

CVE-2022-27668

SAP SAProuter Improper Access Control

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

Dependiendo de la configuración de la tabla de permisos de ruta en el archivo "saprouttab", es posible que un atacante no autenticado ejecute comandos de administración de SAProuter en SAP NetWeaver y ABAP Platform - versiones KERNEL 7. 49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, desde un cliente remoto, por ejemplo deteniendo el SAProuter, lo que podría tener un gran impacto en la disponibilidad de los sistemas

SAP SAProuter suffers from an improper access control vulnerability where permitting loopback traffic can lead to unexpected behavior.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-03-23 CVE Reserved
  • 2022-06-14 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-09-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.49
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.77
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.77"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.81
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.81"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.85
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.85"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.86
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.86"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.87
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.87"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap
Search vendor "Sap" for product "Netweaver As Abap"
kernel_7.88
Search vendor "Sap" for product "Netweaver As Abap" and version "kernel_7.88"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap Krnl64nuc
Search vendor "Sap" for product "Netweaver As Abap Krnl64nuc"
7.49
Search vendor "Sap" for product "Netweaver As Abap Krnl64nuc" and version "7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver As Abap Krnl64uc
Search vendor "Sap" for product "Netweaver As Abap Krnl64uc"
7.49
Search vendor "Sap" for product "Netweaver As Abap Krnl64uc" and version "7.49"
-
Affected
Sap
Search vendor "Sap"
Router
Search vendor "Sap" for product "Router"
7.22
Search vendor "Sap" for product "Router" and version "7.22"
-
Affected
Sap
Search vendor "Sap"
Router
Search vendor "Sap" for product "Router"
7.53
Search vendor "Sap" for product "Router" and version "7.53"
-
Affected