CVE-2022-22536
published 2022-02-09CVE-2022-22536: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for…
PriorityP198critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-09-08
Exploited in the wild
EPSS
97.95%
99.9th percentile
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | content_server | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
| sap | web_dispatcher | — | — |
Detection & IOCsextracted from sources · hover to see the quote
path/sap/public/bc/ur/Login/assets/corbu/sap_logo.png
othershodan-query: http.favicon.hash:-266008933
otherfofa-query: icon_hash=-266008933
commandGET {{sap_path}} HTTP/1.1
Host: {{Hostname}}
Content-Length: 82646
Connection: keep-alive
{{repeat("A", 82642)}}
GET / HTTP/1.1
Host: {{Hostname}}
command0\r\n\r\nGET /sap/bc/webdynpro/sap/appl_soap_management HTTP/1.1\r\nHost: 127.0.0.1\r\nX-Forwarded-For: 127.0.0.1\r\nConnection: close\r\n\r\n↗
- →Detect oversized Content-Length in HTTP requests to SAP paths: a smuggling payload uses Content-Length: 82646 with a body of 82642 'A' characters followed by a second embedded HTTP request.
- →Look for concatenated/smuggled HTTP responses containing 'HTTP/1.0 400 Bad Request', 'HTTP/1.0 500 Internal Server Error', or 'HTTP/1.0 500 Dispatching Error' in a single TCP stream response body — these indicate successful MPI desync exploitation.
- →Monitor for POST requests to /sap/admin/public/default.html with a body beginning with '0\r\n\r\n' followed by an embedded GET request targeting internal loopback paths such as /heapdump/ or /ctc/ConfigServlet — this is the SAPGateBreaker ACL bypass pattern. ↗
- →Network scan detection: Dragos KP-2022-004 includes a detection for traffic associated with scans to identify SAP systems affected by CVE-2022-22536 (CVSSv3 10.0). ↗
- →Use Google dork 'inurl:"/sap/admin/public/default.html"' to identify externally exposed SAP admin interfaces that are prime targets for CVE-2022-22536 exploitation. ↗
- →Indicator of successful exploitation: a status code 200 response for internal SAP endpoints (e.g., /heapdump/) that would normally return 403/404 when accessed directly — compare direct vs. smuggled response codes. ↗
- ·The Onapsis scanner script is a best-effort detection tool and cannot provide 100% accuracy in identifying vulnerable SAP instances. ↗
- ·CVE-2022-22536 affects SAP NetWeaver Java or ABAP applications with DEFAULT configurations — non-default hardened deployments may reduce exposure but are not explicitly confirmed safe. ↗
- ·The ICM component is exposed by default in most SAP deployments because it connects SAP applications to the internet, making the attack surface very broad. ↗
- ·The exploit uses 'unsafe: true' and 'read-all: true' Nuclei flags, meaning the detection template sends raw/malformed HTTP that may disrupt vulnerable SAP services during scanning.
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hc3-539h-6xc6: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7
ghsa_unreviewed·2022-02-11
CVE-2022-22536 [CRITICAL] CWE-444 GHSA-6hc3-539h-6xc6: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
VulnCheck
SAP Multiple Products HTTP Request Smuggling Vulnerability
vulncheck·2022·CVSS 10.0
CVE-2022-22536 [CRITICAL] CWE-444 SAP Multiple Products HTTP Request Smuggling Vulnerability
SAP Multiple Products HTTP Request Smuggling Vulnerability
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
Affected: SAP Multiple Products
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/; https://cisa.gov/news-events/cybersecurity-advisories/aa23-215a; https://dashboard.shadowserver.org/statistics/honeypot/v
CISA
SAP Multiple Products HTTP Request Smuggling Vulnerability
cisa·2022-08-18·CVSS 10.0
CVE-2022-22536 [CRITICAL] CWE-444 SAP Multiple Products HTTP Request Smuggling Vulnerability
Vulnerability: SAP Multiple Products HTTP Request Smuggling Vulnerability
Affected: SAP Multiple Products
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
Required Action: Apply updates per vendor instructions.
Notes: SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536
Remediation Due Date: 2022-09-08
Suricata
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M2
suricata·2022-02-11·CVSS 10.0
CVE-2022-22536 [CRITICAL] ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M2
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M2
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M2"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/sap/admin/public/default.html?"; fast_pattern; http.content_len; byte_test:0,>=,82642,0,string,dec; reference:cve,2022-22536; classtype:attempted-admin; sid:2035183; rev:2; metadata:attack_target Server, created_at 2022_02_11, cve CVE_2022_22536, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2022_02_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_techni
Suricata
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M1
suricata·2022-02-11·CVSS 10.0
CVE-2022-22536 [CRITICAL] ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M1
ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M1
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SAP ICM MPI Desynchronization Scanning Activity (CVE-2022-22536) M1"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/sap/public/bc/ur/Login/assets/corbu/sap_logo.png"; fast_pattern; http.content_len; byte_test:0,>=,82642,0,string,dec; reference:cve,2022-22536; classtype:attempted-admin; sid:2035182; rev:2; metadata:attack_target Server, created_at 2022_02_11, cve CVE_2022_22536, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2022_02_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
exploitdb·2025-04-02·CVSS 10.0
CVE-2022-22536 [CRITICAL] SAP NetWeaver - 7.53 - HTTP Request Smuggling
SAP NetWeaver - 7.53 - HTTP Request Smuggling
---
# Exploit Title: SAPGateBreaker Exploit - CVE-2022-22536 - HTTP Request Smuggling Through SAP's Front Door
# Google Dork: https://github.com/BecodoExploit-mrCAT/SAPGateBreaker-Exploit/blob/main/dorks
# Date: Tuesday, April 2, 2025
# Exploit Author: @C41Tx90 - Victor de Queiroz - Beco do Exploit - Elytron Security
# Vendor Homepage: https://community.sap.com/t5/technology-blogs-by-members/remediation-of-cve-2022-22536-request smuggling-and-request-concatenation/ba-p/13528083
# Software Link: https://help.sap.com/docs/SUPPORT_CONTENT/uiwits/3361892375.html
# Version: SAP NetWeaver Application Server ABAP, SAP NetWeaver
Application Server Java, ABAP Platform, SAP Content Server 7.53 and
SAP Web Dispatcher
# Tested on: Red Hat Enterprise Linu
Nuclei
SAP Memory Pipes (MPI) Desynchronization
nuclei·CVSS 10.0
CVE-2022-22536 [CRITICAL] SAP Memory Pipes (MPI) Desynchronization
SAP Memory Pipes (MPI) Desynchronization
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable to request smuggling and request concatenation attacks. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Template:
id: CVE-2022-22536
info:
name: SAP Memory Pipes (MPI) Desynchronization
author: pdteam
severity: critical
description: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19·CVSS 8.8
CVE-2021-20166 [HIGH] Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Yue Guan
Published: August 19, 2022
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-20166
CVE-2021-20167
CVE-2021-21881
CVE-2021-24762
CVE-2021-28169
CVE-2021-31589
CVE-2021-39226
CVE-2021-4045
CVE-2021-43711
CVE-2022-21371
CVE-2022-21662
CVE-2022-22536
CVE-2022-22947
CVE-2022-22954
CVE-2022-22963
CVE-2022-22965
CVE-2022-24112
CVE-2022-24260
CVE-2022-25060
CVE-2022-25075
CVE-2022-25134
CVE-2022-27226
CVE-2022-29464
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders includ
Dragos
New Knowledge Pack Released (KP-2022-004)
blogs_dragos·2022-04-15
New Knowledge Pack Released (KP-2022-004)
Blog
# New Knowledge Pack Released (KP-2022-004)
April 15, 2022 07:13 PM3 min readDragos, Inc.
This Knowledge Pack includes a group of detections focused on the CHERNOVITE activity group, recently announced by Dragos, and PIPEDREAM – a modular ICS attack framework that an adversary could leverage to cause disruption, degradation, and possibly even destruction depending on targets and the environment.
CHERNOVITE’s PIPEDREAM can execute 38 percent of known ICS attack techniques and 83 percent of known ICS attack tactics.1 PIPEDREAM can manipulate a wide variety of industrial programmable logic controllers (PLC) and industrial software, including Omron and Schneider Electric controllers, and can attack ubiquitous industrial technologies including CODESYS, Modbus, and Open Platform Communi
Dragos
New Knowledge Pack Released (KP-2022-004)
blogs_dragos·2022-04-15
New Knowledge Pack Released (KP-2022-004)
This Knowledge Pack includes a group of detections focused on the CHERNOVITE activity group, recently announced by Dragos, and PIPEDREAM – a modular ICS attack framework that an adversary could leverage to cause disruption, degradation, and possibly even destruction depending on targets and the environment.
CHERNOVITE’s PIPEDREAM can execute 38 percent of known ICS attack techniques and 83 percent of known ICS attack tactics. 1 PIPEDREAM can manipulate a wide variety of industrial programmable logic controllers (PLC) and industrial software, including Omron and Schneider Electric controllers, and can attack ubiquitous industrial technologies including CODESYS, Modbus, and Open Platform Communications Unified Architecture (OPC UA). Together, PIPEDREAM can affect a significant percentage of
Tenable
CVE-2022-22536: SAP Patches Internet Communication Manager Advanced Desync (ICMAD) Vulnerabilities
blogs_tenable·2022-02-09·CVSS 10.0
[CRITICAL] CVE-2022-22536: SAP Patches Internet Communication Manager Advanced Desync (ICMAD) Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
arxiv_fulltext·2025-11-14
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
: A New Benchmark for Evaluating LLMs on Patching
Real-World Vulnerabilities
Zichao Wei^1 *, Jun Zeng^2+, Ming Wen^1 +, Zeliang Yu^1 , Kai Cheng^1, Yiding Zhu^1,
Jingyi Guo^1, Shiqi Zhou^2, Le Yin^2, Xiaodong Su^2, Zhechao Ma^2 \ 0.2em]
^1Huazhong University of Science and Technology ^2ByteDance
footnote
[1]Work done as an intern in ByteDance. ^+Corresponding author.
3pt^ National Engineering Research Center for Big Data Technology and System, Services Computing Technology and System Lab,
Hubei Engineering Research Center on Big Data Security, Hubei Key Laboratory of Distributed System Security, School of Cyber Science and Engineering, HUST, China.
empty
### Abstract
Software vulnerabilities are increasing at an alarming rate.
However, manual patching is both time-consuming and res
https://launchpad.support.sap.com/#/notes/3123396https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlhttps://launchpad.support.sap.com/#/notes/3123396https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22536
2022-02-09
Published
2022-08-18
Added to CISA KEV
Exploited in the wild