← Vulnerability feed

Vulnerability record · CVE-2022-22536 · published 9 February 2022

CVE-2022-22536: SAP NetWeaver and Web Dispatcher HTTP request smuggling

Sap · Content Server

SAP NetWeaver Application Server ABAP, NetWeaver Application Server Java, ABAP Platform, Content Server 7.53 and Web Dispatcher mishandle HTTP requests, allowing request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data, which can lead to impersonation of the victim or poisoning of intermediary web caches. The flaw affects confidentiality, integrity and availability of the whole system.

10.0 CVSS 3.1 Critical CISA KEV since 18 Aug 2022 EPSS 98% · top 0.1% CWE-444 · HTTP request smuggling
10.0CVSS 3.1 base score, v2 10.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network exploitation, KEV listing and very high EPSS probability make this a top remediation priority.

What it is

SAP NetWeaver Application Server ABAP, NetWeaver Application Server Java, ABAP Platform, Content Server 7.53 and Web Dispatcher mishandle HTTP requests, allowing request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data, which can lead to impersonation of the victim or poisoning of intermediary web caches. The flaw affects confidentiality, integrity and availability of the whole system.

Impact

An attacker can execute functions while impersonating another user and poison intermediary caches, potentially leading to complete compromise of confidentiality, integrity and availability.

Attack surface

Reachable over the network via HTTP requests to the affected SAP components; the CVSS vector shows no privileges or user interaction required. No specific endpoint or version detail is given in the record.

Exploitation

Listed in CISA KEV since 2022-08-18 with a required action to apply vendor updates, and EPSS probability is 0.97945 (percentile 0.99906), indicating active exploitation is expected. No ransomware campaign use is documented.

What to do

  • Apply the SAP security note 3123396 updates for NetWeaver AS ABAP, NetWeaver AS Java, ABAP Platform, Content Server 7.53 and Web Dispatcher.
  • If patching cannot be done immediately, restrict or monitor direct HTTP access to affected SAP components and web dispatchers.
  • Review and harden intermediary cache and proxy configurations to reduce request smuggling and cache poisoning exposure.
  • Verify that all affected SAP instances and dispatchers are inventoried so none are missed during remediation.

Detection

  • Inspect HTTP traffic for malformed or concatenated requests, duplicate Content-Length or Transfer-Encoding headers, and smuggling patterns.
  • Monitor web server and dispatcher logs for anomalous request sequences or unexpected cache behavior.
  • Correlate authentication and application logs for actions performed by users who did not initiate them, indicating impersonation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22536 to the Known Exploited Vulnerabilities catalog on 18 August 2022 as "SAP Multiple Products HTTP Request Smuggling Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 September 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22536 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-0488Sap netweaver application server abap missing authorization vulnerabilityAn authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…EPSS 0.51%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%9.8CVE-2023-0014Sap netweaver application server abap authentication bypass by capture-replay vulnerabilitySAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERN…EPSS 0.69%9.8CVE-2021-44231Sap abap platform code injection vulnerabilityInternally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…EPSS 1.3%9.8CVE-2021-40499Sap netweaver application server abap code injection vulnerabilityClient-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…EPSS 1.2%9.8CVE-2021-27610Sap netweaver abap improper authentication vulnerabilitySAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about…EPSS 1.3%9.8CVE-2020-6275Sap netweaver application server abap server-side request forgery (ssrf) vulnerabilitySAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attac…EPSS 1.4%9.6CVE-2023-27501Sap netweaver application server abap path traversal vulnerabilitySAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to ex…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2022-22536), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.