Exploited Vulnerabilities Daily
🌐 English

Home › SAP

CVE-2022-22536: SAP Multiple Products

EPSS97.9%No. 273 of 1739 in KEV
CVE year2022listed the same year
Same vendor in KEV14
Same product1
FieldValue
VendorSAP
ProductMultiple Products
NameSAP Multiple Products HTTP Request Smuggling Vulnerability
Added to KEV2022-08-18
US federal due date2022-09-08
Ransomware useUnknown
CWECWE-444

CISA description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

NVD — CVE-2022-22536

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A SAP Multiple Products vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-18.