CVE-2022-22536
KEVmassHTTP Request Smuggling in SAP NetWeaver, Web Dispatcher and Content Server
CISA: SAP Multiple Products HTTP Request Smuggling Vulnerability
CVE-2022-22536 (CWE-444) is an HTTP request smuggling and request concatenation flaw in the Internet Communication Manager components of SAP NetWeaver Application Server ABAP and Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher. An unauthenticated remote attacker sends crafted HTTP requests whose framing is interpreted inconsistently by intermediary and back-end components, allowing arbitrary attacker-controlled data to be prepended to a victim's request. This lets the attacker execute functions impersonating the victim or poison intermediary web caches, and a successful attack could result in complete compromise of the confidentiality, integrity and availability of the system (CVSS 10.0). Any organization running the affected SAP components is exposed, especially internet-facing SAP systems and those fronted by reverse proxies or caches where front-end/back-end parsing differs. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18 and EPSS assigns a 97.9% probability of exploitation within 30 days, although no public PoC is known and ransomware use is unconfirmed.
What to do: Apply SAP's security updates per vendor instructions for CVE-2022-22536 (SAP Note 3123396), prioritizing internet-facing Web Dispatcher, ICM/NetWeaver and Content Server 7.53 systems as required by the CISA KEV listing. Until patched, restrict direct HTTP access to affected SAP components, review front-end proxies/caches for HTTP framing mismatches, and monitor for anomalous request concatenation or impersonation. Ransomware linkage is unknown, so treat this as general web-application exploitation risk.
| SAP NetWeaver Application Server ABAP | — |
| SAP NetWeaver Application Server Java | — |
| SAP ABAP Platform | — |
| SAP Content Server | 7.53 |
| SAP Web Dispatcher | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
- Affected
- SAP Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- content server, netweaver application server abap, web dispatcher
- Weakness
- CWE-444
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H