CVE-2022-41212 - CVE House
Back to Database
Status published Medium CVE-2022-41212

Due to insufficient input validation, SAP NetWeaver Application Server ABAP...

Vulnerability Description

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41212

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP NetWeaver Application Server ABAP and ABAP Platform
Vulnerable Versions:
= 700, = 731, = 804, = 740, = 750, = 789

Timeline

Official Publish: November 8th, 2022
Last Modified: May 2nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)