Junglewise Threat Intelligence

CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerability

CVE-2022-22536 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-08-18

Technologies: SAP Netweaver Application Server Java, SAP NetWeaver Application Server ABAP, Apple Multiple Products. Vendors: SAP, Apple.

Executive brief

SAP NetWeaver Application Server (ABAP and Java), ABAP Platform, Content Server, and Web Dispatcher are vulnerable to HTTP request smuggling and concatenation. An unauthenticated attacker can prepend arbitrary data to a victim's request, enabling function execution under the victim's identity or poisoning of intermediary web caches.

Affected products

  • SAP NetWeaver Application Server ABAP 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 8.04
  • SAP NetWeaver Application Server Java
  • SAP ABAP Platform
  • SAP Content Server 7.53
  • SAP Web Dispatcher

Timeline

  • 2022-08-18: disclosed
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats