ZeroHour
The Recordpublished ()ingested

CISA and SAP warn about major vulnerability

criticalVulnerabilityimportance 60CVE-2022-22536

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22536
HTTP Request Smuggling in SAP NetWeaver, Web Dispatcher and Content Server

CVE-2022-22536 (CWE-444) is an HTTP request smuggling and request concatenation flaw in the Internet Communication Manager components of SAP NetWeaver Application Server ABAP and Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher. An unauthenticated remote attacker sends crafted HTTP requests whose framing is interpreted inconsistently by intermediary and back-end components, allowing arbitrary attacker-controlled data to be prepended to a victim's request. This lets the attacker execute functions impersonating the victim or poison intermediary web caches, and a successful attack could result in complete compromise of the confidentiality, integrity and availability of the system (CVSS 10.0). Any organization running the affected SAP components is exposed, especially internet-facing SAP systems and those fronted by reverse proxies or caches where front-end/back-end parsing differs. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18 and EPSS assigns a 97.9% probability of exploitation within 30 days, although no public PoC is known and ransomware use is unconfirmed.

Do: Apply SAP's security updates per vendor instructions for CVE-2022-22536 (SAP Note 3123396), prioritizing internet-facing Web Dispatcher, ICM/NetWeaver and Content Server 7.53 systems as required by the CISA KEV listing. Until patched, restrict direct HTTP access to affected SAP components, review front-end proxies/caches for HTTP framing mismatches, and monitor for anomalous request concatenation or impersonation. Ransomware linkage is unknown, so treat this as general web-application exploitation risk.

10.098% KEV
  • SAP NetWeaver Application Server ABAP
  • SAP NetWeaver Application Server Java
  • SAP ABAP Platform
  • +2 more
mass≈100,000+ SAP systems globally (large-enterprise installed base; tens of thousands internet-exposed)
Full article476 words · extracted from therecord.media · click to collapse

German enterprise software maker SAP and the US Cybersecurity and Infrastructure Security Agency have issued security advisories on Tuesday to warn SAP customers to install the company's February security patches as soon as possible in order to prevent the exploitation of a major vulnerability in a ubiquitous SAP component.

Tracked as CVE-2022-22536, the vulnerability was discovered by cloud security firm Onapsis and impacts the SAP Internet Communication Manager (ICM).

The main purpose of this component is to provide a working HTTPS web server for all SAP products that need to be connected to the internet or talk to each other via HTTP/S, meaning that if a vulnerability is present in its code, entire SAP products are exposed to attacks 24/7.

In a report published yesterday, Onapsis said that CVE-2022-22536 is one of those dangerous bugs, allowing attackers to use malformed packets that trick SAP servers into exposing sensitive data without the attacker needing to authenticate.

The attack, known as HTTP request smuggling, could be used to steal credentials and session information from unpatched SAP servers, even if servers are placed behind proxies, Onapsis said.

"What makes these vulnerabilities particularly critical for SAP customers is the fact that the issues are present by default in the ICM component," researchers explained.

"A simple HTTP request, indistinguishable from any other valid message and without any kind of authentication, is enough for a successful exploitation."

Patches are already out, but attack surface is massive

SAP patched the issue yesterday. CVE-2022-22536 is one of eight vulnerabilities that received a severity rating of 10/10 but is the one that CISA chose to highlight in its own security advisory, primarily due to its ease of exploitation and its ubiquity in SAP products.

According to SAP, known affected products include SAP WebDispatcher, SAP Content Server, SAP ABAP, and SAP NetWeaver—one of SAP's most popular offerings.

According to a Shodan search, there are more than 5,000 SAP NetWeaver servers currently connected to the internet and exposed to attacks, lest a patch is installed.

Since the ICM component may be active in other SAP product setups, Onapsis has also released a Python script so SAP customers can test their setups and see if they are vulnerable to attacks.

In a blog post yesterday, SAP Director of Security Response Vic Chung confirmed the severity of Onapsis' findings and asked customers to apply the patches as soon as possible.

CISA warned that customers who fail to do so will be exposing themselves to ransomware attacks, the theft of sensitive data, financial fraud, and disruption or halt of business operations.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-and-sap-warn-about-major-vulnerability