sap netweaver-application-server-java CVE-2022-22533 is a vulnerability in SAP Netweaver Application Server Java
Published on February 9, 2022

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system unavailable.

NVD

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2022-22533 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2022-22533

Want to know whenever a new CVE is published for SAP Netweaver Application Server Java? stack.watch will email you.

 

Affected Versions

SAP SE SAP NetWeaver Application Server Java:

Exploit Probability

EPSS
0.75%
Percentile
72.89%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.