Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2022-22536

SAP Multiple Products HTTP Request Smuggling Vulnerability

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

cat cve-2022-22536.json
Vendor
SAP
Product
Multiple Products
CVSS
10.0
EPSS (exploit probability)
97.9%
Status
kev
CISA patch-by (BOD 22-01)
Published

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim’s request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2022-08-18. Required action per CISA: Apply updates per vendor instructions. Due date: 2022-09-08.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.