CVE-2024-22132 HIGH

CVE-2024-22132: Code Injection vulnerability in SAP IDES Systems

Vendor Sap_Se
Product SAP IDES Systems
Weakness CWE-78
Published February 13, 2024
Last update April 24, 2025

CVSS base score

7.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behaviour of the system by executing malicious code which can potentially escalate privileges with low impact on confidentiality, integrity and availability of the system.

Key dates

02Disclosure timeline

February 13, 2024 CVE published
April 24, 2025 Record updated