CVE-2022-22536
Description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Summary dbcve.org
This is an HTTP request smuggling vulnerability in SAP NetWeaver Application Servers (ABAP and Java), ABAP Platform, SAP Content Server, and SAP Web Dispatcher. An unauthenticated attacker can prepend arbitrary data to a victim's HTTP request, enabling request concatenation that bypasses authentication controls and poisons web caches. The CVSS 10 score confirms complete compromise of confidentiality, integrity, and availability.
Mitigation
Apply the relevant SAP Security Note for CVE-2022-22536 immediately to all affected SAP components. As a compensating control, restrict external access to affected SAP interfaces via network segmentation or WAF rules until patches are applied.