⚠ Actively exploited
Added to CISA KEV on 2022-08-18. Federal agencies required to patch by 2022-09-08. Required action: Apply updates per vendor instructions..

CVE-2022-22536

Severity
10.0CRITICAL
EPSS
93.8%
top 0.14%
CISA KEV
KEV
Added 2022-08-18
Due 2022-09-08
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedFeb 9
KEV addedAug 18
KEV dueSep 8
Latest updateApr 2
CISA Required Action: Apply updates per vendor instructions.

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the s

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages6 packages

CVEListV5sap_se/sap_netweaver_and_abap_platform13 versions+12
NVDsap/netweaver_application17 versions+16
NVDsap/web_dispatcher8 versions+7

🔴Vulnerability Details

3
GHSA
GHSA-6hc3-539h-6xc6: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 72022-02-11
CVEList
CVE-2022-22536: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 72022-02-09
VulnCheck
SAP Multiple Products HTTP Request Smuggling Vulnerability2022

💥Exploits & PoCs

2
Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling2025-04-02
Nuclei
SAP Memory Pipes (MPI) Desynchronization

🔍Detection Rules

2
Suricata
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M22022-02-11
Suricata
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M12022-02-11

📋Vendor Advisories

1
CISA
SAP Multiple Products HTTP Request Smuggling Vulnerability2022-08-18

🕵️Threat Intelligence

1
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More2022-08-19
CVE-2022-22536 (CRITICAL CVSS 10) | SAP NetWeaver Application Server AB | cvebase.io