CVE-2022-22536 is a critical request smuggling and concatenation vulnerability affecting SAP NetWeaver Application Server ABAP and Java, ABAP Platform, SAP Content Server 7.53, and SAP Web Dispatcher. An unauthenticated attacker can manipulate victim requests, potentially impersonating users or poisoning web caches. With a CVSS score of 10.0, this flaw allows for complete compromise of confidentiality, integrity, and availability due to its network-based attack vector and low complexity. This vulnerability is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit code and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.53CPE matchmatch criteria | cpe:2.3:a:sap:content_server:7.53:*:*:*:*:*:*:* | ||
7.22CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:7.22:*:*:*:*:*:*:* | ||
7.49CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:7.49:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:7.53:*:*:*:*:*:*:* | ||
7.77CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:7.77:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.