SAP Knowledge Base Article - Preview

3442135 - [CVE-2022-1471]SnakeYAML Deserialization Vulnerability in Introscope Enterprise Manager

Symptom

SnakeYAML is an open-source code library that converts YAML files into Java objects, which is used in Introscope Enterprise Manager. A serious Deserialization Vulnerability (CVE-2022-1471) is detected in it.


Read more...

Environment

  • Introscope Enterprise Manager 9.X
  • Introscope Enterprise Manager 10.X

Product

SAP Solution Manager 7.2

Keywords

Introscope Enterprise Manager, EM, Introscope EM, CVE-2022-1471, SnakeYAML, SnakeYAML Deserialization Vulnerability, YAML, vulnerabilities , KBA , XX-PART-WILY , Introscope by CA Technologies , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.