CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:content_server:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.77:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.81:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.85:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.86:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:7.87:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:8.04:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64nuc_7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64nuc_7.22ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64nuc_7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64uc_7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64uc_7.22ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64uc_7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64uc_7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:krnl64uc_8.04:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.22ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.77:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.81:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.85:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.86:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.87:*:*:*:*:*:*:*

History

21 Nov 2024, 06:46

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3123396 - Permissions Required () https://launchpad.support.sap.com/#/notes/3123396 - Permissions Required
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Not Applicable, Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Not Applicable, Vendor Advisory

28 Jun 2024, 14:08

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3123396 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/3123396 - Permissions Required
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Not Applicable, Vendor Advisory

27 Sep 2023, 15:15

Type Values Removed Values Added
Summary SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system. SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Information

Published : 2022-02-09 23:15

Updated : 2024-11-21 06:46


NVD link : CVE-2022-22536

Mitre link : CVE-2022-22536

CVE.ORG link : CVE-2022-22536


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
  • web_dispatcher
  • content_server
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')