Umbra Wiki cve cve/CVE-2022-22536
Back to wiki

CVE-2022-22536 — SAP Multiple Products HTTP Request Smuggling Vulnerability

provenance: imported · CVE: CVE-2022-22536 · CWE: CWE-444

CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SAP
Product Multiple Products
Date added 2022-08-18
Due date 2022-09-08
Ransomware campaign use Unknown

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

Required action (CISA)

Apply updates per vendor instructions.

Notes

SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536

Weakness behind it

CISA records this vulnerability as an instance of CWE-444. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-22536
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →