CVE-2022-22536
CRITICAL KEV NUCLEISAP NetWeaver - Request Smuggling
Title source: llmDescription
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Exploits (8)
nomisec
WORKING POC
10 stars
by tess-ss · poc
https://github.com/tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536
nomisec
WORKING POC
1 stars
by BecodoExploit-mrCAT · infoleak
https://github.com/BecodoExploit-mrCAT/SAPGateBreaker-Exploit
nomisec
SCANNER
by abrewer251 · infoleak
https://github.com/abrewer251/CVE-2022-22536_SAP_Request_Smuggling_Scanner
inthewild
WRITEUP
poc
https://github.com/tes5hacks/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536
inthewild
WORKING POC
poc
https://github.com/asurti6783/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536
Nuclei Templates (1)
SAP Memory Pipes (MPI) Desynchronization
CRITICALby pdteam
Shodan:
http.favicon.hash:-266008933
FOFA:
icon_hash=-266008933
References (3)
Scores
CVSS v3
10.0
EPSS
0.9383
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2022-08-18
VulnCheck KEV
2022-08-18
InTheWild.io
2022-08-18
ENISA EUVD
EUVD-2022-27682
CWE
CWE-444
Status
published
Products (26)
sap/content_server
7.53
sap/netweaver_application_server_abap
7.22
sap/netweaver_application_server_abap
7.49
sap/netweaver_application_server_abap
7.53
sap/netweaver_application_server_abap
7.77
sap/netweaver_application_server_abap
7.81
sap/netweaver_application_server_abap
7.85
sap/netweaver_application_server_abap
7.86
sap/netweaver_application_server_abap
7.87
sap/netweaver_application_server_abap
8.04
... and 16 more
Published
Feb 09, 2022
KEV Added
Aug 18, 2022
Tracked Since
Feb 18, 2026