← Vulnerability feed

Vulnerability record · CVE-2022-22543 · published 9 February 2022

CVE-2022-22543: Sap netweaver abap uncontrolled resource consumption vulnerability

Sap · Netweaver Abap

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service attack. This allows an unauthorized remote user to provoke a breakdown of the SAP Web Dispatcher or Kernel work process. The crashed process can be restarted immediately, other processes are not affected.

7.5 CVSS 3.1 High EPSS 1.4% · top 29.3% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service attack. This allows an unauthorized remote user to provoke a breakdown of the SAP Web Dispatcher or Kernel work process. The crashed process can be restarted immediately, other processes are not affected.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-4341Sap netweaver abap memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and exe…EPSS 8.7%9.8CVE-2022-27668Sap netweaver as abap incorrect authorization vulnerabilityDepending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute…EPSS 2.2%9.8CVE-2021-27610Sap netweaver abap improper authentication vulnerabilitySAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about…EPSS 1.3%8.8CVE-2021-38178Sap netweaver abap vulnerabilityThe software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, …EPSS 1.3%8.8CVE-2019-0257Sap netweaver application server abap missing authorization vulnerabilityCustomizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.…EPSS 1.4%7.5CVE-2021-38181Sap netweaver abap vulnerabilitySAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent leg…EPSS 1.1%7.5CVE-2021-33677Sap netweaver abap vulnerabilitySAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to inform…EPSS 0.94%7.5CVE-2021-27633Sap netweaver abap out-of-bounds write vulnerabilitySAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2022-22543), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.