CVE-2022-22536

Confirmed PUBLISHED

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...

SAP SE · SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 97.9%

At a Glance

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

cisa java nuclei_scanner
CVE Published
Feb 09, 2022
Exploitation Reported
Aug 18, 2022
CVSS
10.0 Critical
EPSS
97.9%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
SAP SE
SAP NetWeaver and ABAP Platform

KERNEL 7.22

Affected
SAP SE
SAP NetWeaver and ABAP Platform

8.04

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.49

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.53

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.77

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.81

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.85

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.86

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.87

Affected
SAP SE
SAP NetWeaver and ABAP Platform

KRNL64UC 8.04

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.22

Affected
SAP SE
SAP NetWeaver and ABAP Platform

7.22EXT

Affected
SAP SE
SAP NetWeaver and ABAP Platform

KRNL64NUC 7.22

Affected
SAP SE
SAP Web Dispatcher

7.49

Affected
SAP SE
SAP Web Dispatcher

7.53

Affected
SAP SE
SAP Web Dispatcher

7.77

Affected
SAP SE
SAP Web Dispatcher

7.81

Affected
SAP SE
SAP Web Dispatcher

7.85

Affected
SAP SE
SAP Web Dispatcher

7.22EXT

Affected
SAP SE
SAP Web Dispatcher

7.86

Affected
SAP SE
SAP Web Dispatcher

7.87

Affected
SAP SE
SAP Content Server

7.53

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.