CVE-2022-22532
published 2022-02-09CVE-2022-22532: In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an…
PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.37%
81.9th percentile
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be executed and hence execute functions that could be impersonating the victim or even steal the victim's logon session.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_application_server_java | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-22532 is exploitable via a crafted HTTP server request targeting the ICM component of SAP NetWeaver Application Server Java; detection should focus on anomalous or malformed HTTP requests to SAP ICM endpoints ↗
- →CVE-2022-22532 is classified as both HTTP request smuggling and use-after-free in the ICM component; monitor for HTTP request smuggling patterns (e.g., conflicting Content-Length/Transfer-Encoding headers) against SAP NetWeaver Java systems ↗
- →No authentication or user interaction is required to exploit CVE-2022-22532; treat any unauthenticated access to SAP ICM HTTP endpoints as potentially malicious in the context of this CVE ↗
- →CVE-2022-22532 only affects SAP NetWeaver Application Server Java; scope detection to Java-based SAP AS instances running KRNL64NUC 7.22/7.22EXT/7.49, KRNL64UC 7.22/7.22EXT/7.49/7.53, KERNEL 7.22/7.49/7.53 ↗
- →Successful exploitation could allow session hijacking (stealing victim logon session) or impersonation; monitor for anomalous session reuse or privilege escalation following HTTP requests to SAP ICM ↗
- ·CVE-2022-22532 is patched by SAP Security Note 3123427; unpatched systems running the affected kernel versions remain vulnerable ↗
- ·The ICM component is exposed by default in most SAP deployments because it connects SAP applications to the internet, widening the attack surface for this vulnerability ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2022-02-09
Published