CVE-2022-22536

NVD Published Date: February 09, 2022 at 11:15 PM
NVD Last Modified: June 28, 2024 at 02:08 PM
Download Patch
Vulnerability ID
CVE-2022-22536
Severity
CRITICAL
Severity Score
10.0
Summary
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Mitigation and Patches
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-444

Recent Publish

KB5046616

KB5046617

CVE-2022-0543

CVE-2022-22947

KB5046618

KB5046630

See More ...

See SecOps Solution
in action

Schedule Demo