Vulnerability Intelligence Report
SAP Multiple Products HTTP Request Smuggling Vulnerability
CVE-2022-22536
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:97.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-444 ↗CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP SE | SAP NetWeaver and ABAP Platform | KERNEL 7.22 (affected), 8.04 (affected), 7.49 (affected), 7.53 (affected), 7.77 (affected), 7.81 (affected), 7.85 (affected), 7.86 (affected), 7.87 (affected), KRNL64UC 8.04 (affected), 7.22 (affected), 7.22EXT (affected), KRNL64NUC 7.22 (affected) |
| SAP SE | SAP Web Dispatcher | 7.49 (affected), 7.53 (affected), 7.77 (affected), 7.81 (affected), 7.85 (affected), 7.22EXT (affected), 7.86 (affected), 7.87 (affected) |
| SAP SE | SAP Content Server | 7.53 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
97.945%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2022-01-04T00:00:00 |
| Published | 2022-02-09T22:05:24 |
| Last Updated | 2025-10-21T23:15:47 |
Community Chatter & Buzz