Vulnerability record · CVE-2022-22536 · published 9 February 2022
CVE-2022-22536: SAP NetWeaver and Web Dispatcher HTTP request smuggling
Sap · Content Server
SAP NetWeaver Application Server ABAP, NetWeaver Application Server Java, ABAP Platform, Content Server 7.53 and Web Dispatcher mishandle HTTP requests, allowing request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data, which can lead to impersonation of the victim or poisoning of intermediary web caches. The flaw affects confidentiality, integrity and availability of the whole system.
Description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network exploitation, KEV listing and very high EPSS probability make this a top remediation priority.
What it is
SAP NetWeaver Application Server ABAP, NetWeaver Application Server Java, ABAP Platform, Content Server 7.53 and Web Dispatcher mishandle HTTP requests, allowing request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data, which can lead to impersonation of the victim or poisoning of intermediary web caches. The flaw affects confidentiality, integrity and availability of the whole system.
Impact
An attacker can execute functions while impersonating another user and poison intermediary caches, potentially leading to complete compromise of confidentiality, integrity and availability.
Attack surface
Reachable over the network via HTTP requests to the affected SAP components; the CVSS vector shows no privileges or user interaction required. No specific endpoint or version detail is given in the record.
Exploitation
Listed in CISA KEV since 2022-08-18 with a required action to apply vendor updates, and EPSS probability is 0.97945 (percentile 0.99906), indicating active exploitation is expected. No ransomware campaign use is documented.
What to do
- Apply the SAP security note 3123396 updates for NetWeaver AS ABAP, NetWeaver AS Java, ABAP Platform, Content Server 7.53 and Web Dispatcher.
- If patching cannot be done immediately, restrict or monitor direct HTTP access to affected SAP components and web dispatchers.
- Review and harden intermediary cache and proxy configurations to reduce request smuggling and cache poisoning exposure.
- Verify that all affected SAP instances and dispatchers are inventoried so none are missed during remediation.
Detection
- Inspect HTTP traffic for malformed or concatenated requests, duplicate Content-Length or Transfer-Encoding headers, and smuggling patterns.
- Monitor web server and dispatcher logs for anomalous request sequences or unexpected cache behavior.
- Correlate authentication and application logs for actions performed by users who did not initiate them, indicating impersonation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22536 to the Known Exploited Vulnerabilities catalog on 18 August 2022 as "SAP Multiple Products HTTP Request Smuggling Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 September 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.support.sap.com/#/notes/3123396 | Permissions Required |
| https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Broken LinkNot ApplicableVendor Advisory |
| https://launchpad.support.sap.com/#/notes/3123396 | Permissions Required |
| https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Broken LinkNot ApplicableVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22536 | US Government Resource |
Track CVE-2022-22536 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22536), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.