CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 04, 2022
Published Date
February 09, 2022
Last Updated
January 29, 2025
Vendor
SAP SE
Product
SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server
Description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CVSS Scores

CVSS v3.1

10.0 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-08-18 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2022-04-02 16:12:56 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-08-18 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536

Type: github • Created: 2022-04-02 16:12:56 UTC • Stars: 12

ZZ-SOCMAP/CVE-2022-22536

Type: github • Created: 2022-02-15 09:22:19 UTC • Stars: 51

SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.