Umbra Wiki cve cve/CVE-2022-22536
Back to wiki

CVE-2022-22536 — SAP Multiple Products HTTP Request Smuggling Vulnerability

provenance: imported · CVE: CVE-2022-22536

CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SAP
Product Multiple Products
Date added 2022-08-18
Due date 2022-09-08
Ransomware campaign use Unknown

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

Required action (CISA)

Apply updates per vendor instructions.

Notes

SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-22536
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog