CVE-2022-22536

CRITICAL KEV NUCLEI

SAP NetWeaver - Request Smuggling

Title source: llm

Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Exploits (8)

exploitdb WORKING POC
by C41Tx90 · textremotemultiple
https://www.exploit-db.com/exploits/52109
nomisec WORKING POC 51 stars
by ZZ-SOCMAP · poc
https://github.com/ZZ-SOCMAP/CVE-2022-22536
nomisec WORKING POC 10 stars
by tess-ss · poc
https://github.com/tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536
nomisec WORKING POC 1 stars
by BecodoExploit-mrCAT · infoleak
https://github.com/BecodoExploit-mrCAT/SAPGateBreaker-Exploit
nomisec SCANNER
by abrewer251 · infoleak
https://github.com/abrewer251/CVE-2022-22536_SAP_Request_Smuggling_Scanner
inthewild WRITEUP
poc
https://github.com/tes5hacks/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536
inthewild WORKING POC
poc
https://github.com/asurti6783/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536
inthewild WORKING POC
poc
https://github.com/antx-code/cve-2022-22536

Nuclei Templates (1)

SAP Memory Pipes (MPI) Desynchronization
CRITICALby pdteam
Shodan: http.favicon.hash:-266008933
FOFA: icon_hash=-266008933

Scores

CVSS v3 10.0
EPSS 0.9383
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2022-08-18
VulnCheck KEV 2022-08-18
InTheWild.io 2022-08-18
ENISA EUVD EUVD-2022-27682
CWE
CWE-444
Status published
Products (26)
sap/content_server 7.53
sap/netweaver_application_server_abap 7.22
sap/netweaver_application_server_abap 7.49
sap/netweaver_application_server_abap 7.53
sap/netweaver_application_server_abap 7.77
sap/netweaver_application_server_abap 7.81
sap/netweaver_application_server_abap 7.85
sap/netweaver_application_server_abap 7.86
sap/netweaver_application_server_abap 7.87
sap/netweaver_application_server_abap 8.04
... and 16 more
Published Feb 09, 2022
KEV Added Aug 18, 2022
Tracked Since Feb 18, 2026