← All CVEs

CVE-2022-22536

critical · 10Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-08-18Remediation due 2022-09-08

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

10
CVSS
97.9%
EPSS (exploit prob.)
100th
EPSS percentile
2022-02-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-444

Affected products

VendorProductAffected versions
sapcontent_server7.53
sapnetweaver_application_server_abap7.22
sapnetweaver_application_server_abap7.49
sapnetweaver_application_server_abap7.53
sapnetweaver_application_server_abap7.77
sapnetweaver_application_server_abap7.81
sapnetweaver_application_server_abap7.85
sapnetweaver_application_server_abap7.86
sapnetweaver_application_server_abap7.87
sapnetweaver_application_server_abap8.04
sapnetweaver_application_server_abapkrnl64nuc_7.22
sapnetweaver_application_server_abapkrnl64nuc_7.22ext
sapnetweaver_application_server_abapkrnl64nuc_7.49
sapnetweaver_application_server_abapkrnl64uc_7.22
sapnetweaver_application_server_abapkrnl64uc_7.22ext
sapnetweaver_application_server_abapkrnl64uc_7.49
sapnetweaver_application_server_abapkrnl64uc_7.53
sapnetweaver_application_server_abapkrnl64uc_8.04
sapweb_dispatcher7.22ext
sapweb_dispatcher7.49
sapweb_dispatcher7.53
sapweb_dispatcher7.77
sapweb_dispatcher7.81
sapweb_dispatcher7.85
sapweb_dispatcher7.86
sapweb_dispatcher7.87

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-22536