CVE-2022-22536
SAP Multiple Products HTTP Request Smuggling Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 97.95% probability · 100th percentile
- CISA KEV
- Listed 18 August 2022 · due 8 September 2022
- Weakness
- CWE-444
- Affected
- sap/content server · sap/netweaver application server abap · sap/web dispatcher
- Source
- cna@sap.com
CISA notes
Apply updates per vendor instructions. SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536
References
- https://launchpad.support.sap.com/#/notes/3123396Permissions Required
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlBroken Link, Not Applicable, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3123396Permissions Required
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlBroken Link, Not Applicable, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22536US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.