Executive brief
SAP NetWeaver Application Server (ABAP and Java), ABAP Platform, Content Server, and Web Dispatcher are vulnerable to HTTP request smuggling and concatenation. An unauthenticated attacker can prepend arbitrary data to a victim's request, enabling function execution under the victim's identity or poisoning of intermediary web caches.
Affected products
- SAP NetWeaver Application Server ABAP 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 8.04
- SAP NetWeaver Application Server Java
- SAP ABAP Platform
- SAP Content Server 7.53
- SAP Web Dispatcher
Timeline
- 2022-08-18: disclosed
- 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.