CVE-2022-22536: SAP Multiple Products
EPSS97.9%No. 273 of 1739 in KEV
CVE year2022listed the same year
Same vendor in KEV14
Same product1
| Field | Value |
|---|---|
| Vendor | SAP |
| Product | Multiple Products |
| Name | SAP Multiple Products HTTP Request Smuggling Vulnerability |
| Added to KEV | 2022-08-18 |
| US federal due date | 2022-09-08 |
| Ransomware use | Unknown |
| CWE | CWE-444 |
CISA description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A SAP Multiple Products vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-18.