EXPOSURES › CVE-2022-22536
CVE-2022-22536
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP's NetWeaver products exploited for HTTP request smuggling
An unauthenticated attacker exploited an HTTP request smuggling vulnerability in SAP's NetWeaver products, allowing arbitrary function execution and potential cache poisoning.
Shame score — High severity, actively exploited vulnerability with no known patches, impacting multiple products.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |