Skip to content
COOEY

EXPOSURES › CVE-2022-22536

CVE-2022-22536

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-22536 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

SAP's NetWeaver products exploited for HTTP request smuggling

An unauthenticated attacker exploited an HTTP request smuggling vulnerability in SAP's NetWeaver products, allowing arbitrary function execution and potential cache poisoning.

Shame score — High severity, actively exploited vulnerability with no known patches, impacting multiple products.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized