ZeroHour

CVE-2022-22536

KEVmass

HTTP Request Smuggling in SAP NetWeaver, Web Dispatcher and Content Server

CISA: SAP Multiple Products HTTP Request Smuggling Vulnerability

CVSS 3.1
10.0 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2022-22536 (CWE-444) is an HTTP request smuggling and request concatenation flaw in the Internet Communication Manager components of SAP NetWeaver Application Server ABAP and Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher. An unauthenticated remote attacker sends crafted HTTP requests whose framing is interpreted inconsistently by intermediary and back-end components, allowing arbitrary attacker-controlled data to be prepended to a victim's request. This lets the attacker execute functions impersonating the victim or poison intermediary web caches, and a successful attack could result in complete compromise of the confidentiality, integrity and availability of the system (CVSS 10.0). Any organization running the affected SAP components is exposed, especially internet-facing SAP systems and those fronted by reverse proxies or caches where front-end/back-end parsing differs. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18 and EPSS assigns a 97.9% probability of exploitation within 30 days, although no public PoC is known and ransomware use is unconfirmed.

What to do: Apply SAP's security updates per vendor instructions for CVE-2022-22536 (SAP Note 3123396), prioritizing internet-facing Web Dispatcher, ICM/NetWeaver and Content Server 7.53 systems as required by the CISA KEV listing. Until patched, restrict direct HTTP access to affected SAP components, review front-end proxies/caches for HTTP framing mismatches, and monitor for anomalous request concatenation or impersonation. Ransomware linkage is unknown, so treat this as general web-application exploitation risk.

Affected
SAP NetWeaver Application Server ABAP
SAP NetWeaver Application Server Java
SAP ABAP Platform
SAP Content Server7.53
SAP Web Dispatcher
Estimated exposure
mass≈100,000+ SAP systems globally (large-enterprise installed base; tens of thousands internet-exposed) — SAP NetWeaver/ABAP is the runtime platform for most SAP ERP and business-suite deployments at large enterprises worldwide, and public internet scans routinely show tens of thousands of exposed SAP ICM/Web Dispatcher endpoints, implying a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CISA Known Exploited Vulnerability
Affected
SAP Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sap
Products
content server, netweaver application server abap, web dispatcher
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news