CRITICAL

CVE-2022-22536

Sap Content Server 2022-02-09 CVSS v3.1
CVSS
10
KEV

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Summary dbcve.org

This is an HTTP request smuggling vulnerability in SAP NetWeaver Application Servers (ABAP and Java), ABAP Platform, SAP Content Server, and SAP Web Dispatcher. An unauthenticated attacker can prepend arbitrary data to a victim's HTTP request, enabling request concatenation that bypasses authentication controls and poisons web caches. The CVSS 10 score confirms complete compromise of confidentiality, integrity, and availability.

Mitigation

Apply the relevant SAP Security Note for CVE-2022-22536 immediately to all affected SAP components. As a compensating control, restrict external access to affected SAP interfaces via network segmentation or WAF rules until patches are applied.

Weakness (CWE)

CWE-444

EPSS Score

97.95%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE