August 18, 2022 · Applied Cybernetics Group
CVE-2022-22536 — SAP Multiple Products
SAP Multiple Products HTTP Request Smuggling Vulnerability
- Added to KEV
2022-08-18- Federal due date
2022-09-08- Vendor
- SAP
- Product
- Multiple Products
- EPSS
- 99.9th percentile (score 0.938, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-22536
CISA short description
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
Required action
Apply updates per vendor instructions.