Threat intelligence report · CISA KEV

CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerability

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2022-08-18T00:00:00Z
Confidence basis
No actor match
Record ID
d6c5f5a36d7f2a9e9a91

Vulnerabilities

CVE-2022-22536

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.