// For flags

CVE-2022-29614

SAP SAPControl Web Service Interface Local Privilege Escalation

Severity Score

5.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, - on Unix systems, s-bit helper program sapuxuserchk, can be abused physically resulting in a privilege escalation of an attacker leading to low impact on confidentiality and integrity, but a profound impact on availability.

SAP startservice - de SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform y HANA Database - versiones KERNEL versiones 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49 49, 7.53, SAPHOSTAGENT 7.22, - en los sistemas Unix, el programa de ayuda s-bit sapuxuserchk, puede ser abusado físicamente resultando en una escalada de privilegios de un atacante que conlleva a un bajo impacto en la confidencialidad e integridad, pero un profundo impacto en la disponibilidad

SAPControl Web Service Interface (sapstartsrv) suffers from a privilege escalation vulnerability via a race condition.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-04-25 CVE Reserved
  • 2022-06-14 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-09-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Host Agent
Search vendor "Sap" for product "Host Agent"
7.22
Search vendor "Sap" for product "Host Agent" and version "7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.22
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.49
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.53
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.53"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.77
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.77"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.81
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.81"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.85
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.85"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.86
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.86"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.87
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.87"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_7.88
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_7.88"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64nuc_7.22
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64nuc_7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64nuc_7.22ext
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64nuc_7.22ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64uc_7.22
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64uc_7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64uc_7.22ext
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64uc_7.22ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64uc_7.49
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64uc_7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64uc_7.53
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64uc_7.53"
-
Affected