CVE-2022-22528

Severity
7.8HIGH
EPSS
0.1%
top 69.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateFeb 11

Description

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on the local system. The issue is with the ASE installer and does not impact other ASE binaries.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-fh7g-p43j-mxhc: SAP Adaptive Server Enterprise (ASE) - version 162022-02-11
CVEList
CVE-2022-22528: SAP Adaptive Server Enterprise (ASE) - version 162022-02-09