SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-22536

SAP Multiple Products HTTP Request Smuggling Vulnerability

KEVCRITICAL 10.0EPSS 97.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
97.95% probability · 100th percentile
CISA KEV
Listed 18 August 2022 · due 8 September 2022
Weakness
CWE-444
Affected
sap/content server · sap/netweaver application server abap · sap/web dispatcher
Source
cna@sap.com

CISA notes

Apply updates per vendor instructions. SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.