PT-2022-1739 · Sap · Sap Content Server +4
Published
2022-02-09
·
Updated
2025-05-05
·
CVE-2022-22536
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Application Server ABAP versions 7.53 and earlier
SAP NetWeaver Application Server Java versions 7.53 and earlier
ABAP Platform versions 7.53 and earlier
SAP Content Server versions 7.53 and earlier
SAP Web Dispatcher versions 7.53 and earlier
Description:
An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing the attacker to execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity, and Availability of the system.
Recommendations:
SAP NetWeaver Application Server ABAP versions 7.53 and earlier: Update to a version that includes the security patch for request smuggling and request concatenation.
SAP NetWeaver Application Server Java versions 7.53 and earlier: Update to a version that includes the security patch for request smuggling and request concatenation.
ABAP Platform versions 7.53 and earlier: Update to a version that includes the security patch for request smuggling and request concatenation.
SAP Content Server versions 7.53 and earlier: Update to a version that includes the security patch for request smuggling and request concatenation.
SAP Web Dispatcher versions 7.53 and earlier: Update to a version that includes the security patch for request smuggling and request concatenation.
Exploit
Fix
HTTP Request/Response Smuggling
Weakness Enumeration
Related Identifiers
Affected Products
References · 25
- 🔥 https://github.com/ZZ-SOCMAP/CVE-2022-22536⭐ 50 🔗 18 · Exploit
- 🔥 https://github.com/antx-code/CVE-2022-22536⭐ 50 🔗 18 · Exploit
- 🔥 https://github.com/asurti6783/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/tes5hacks/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536⭐ 11 🔗 5 · Exploit
- https://sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-22536 · Security Note
- https://bdu.fstec.ru/vul/2022-01015 · Security Note
- https://twitter.com/syedaquib77/status/1919500888676434114 · Twitter Post
- https://t.me/poxek/2333 · Telegram Post
- https://cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv · Note
- https://t.me/cybersecuritytechnologies/5421 · Telegram Post
- https://t.me/cvenotify/109089 · Telegram Post
- https://t.me/thehackernews/2494 · Telegram Post
- https://t.me/cvenotify/114657 · Telegram Post