CVE-2022-22536
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
CISA KEV
- Vendor
- SAP
- Product
- Multiple Products
- Due date
- 2022-09-08
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.