10
CVSSv3

CVE-2022-22536

Published: 09/02/2022 Updated: 27/09/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 892
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver application server abap krnl64nuc_7.49

sap netweaver application server abap krnl64uc_7.49

sap netweaver application server abap krnl64uc_7.53

sap web dispatcher 7.53

sap web dispatcher 7.77

sap web dispatcher 7.81

sap web dispatcher 7.22ext

sap web dispatcher 7.49

sap content server 7.53

sap web dispatcher 7.85

sap web dispatcher 7.86

sap web dispatcher 7.87

sap netweaver application server abap krnl64nuc_7.22

sap netweaver application server abap krnl64nuc_7.22ext

sap netweaver application server abap krnl64uc_8.04

sap netweaver application server abap krnl64uc_7.22

sap netweaver application server abap krnl64uc_7.22ext

sap netweaver application server abap 7.22

sap netweaver application server abap 7.49

sap netweaver application server abap 7.53

sap netweaver application server abap 7.77

sap netweaver application server abap 7.81

sap netweaver application server abap 7.85

sap netweaver application server abap 7.86

sap netweaver application server abap 7.87

sap netweaver application server abap 8.04

Github Repositories

a simple exploit of ICMAD vulnerabilty

‌ICMAD Exploit a simple exploit of ICMAD vulnerabilty Note this project is done Our instagram page Our youtube chanel Our twitter page What are the ICMAD Vulnerabilities? SAP ICMAD Vulnerabilities are those vulnerabilities that are present in the ICM component of SAP, including SAP NetWeaver, S/4HANA, a

SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536 What is the vulnerability about? SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 753 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation An unauthenticated attacker can prepend a victim's request with arbitr

SAP penetration testing Web and network cheatsheet

SAP-Pentest-Cheatsheet Bismillah For conducting the Pentest you should deploy SAP System on your Network SAP Web Interface Vulnerability Open Redirection Check HOST/sap/public/bc/icf/logoff?redirecturl=MALICIOUSURL Unsecured Protocol (HTTP) Check HOST:PORT/startPage HOST:PORT/sap/public/info System Informational Misconfiguration Check HOST:POR

SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.

CVE-2022-22536 SAP memory pipes desynchronization vulnerability(MPI) CVE-2022-22536 Description POC for CVE-2022-22536: SAP memory pipes(MPI) desynchronization vulnerability create by antx at 2022-02-15 Detail SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 753 and SAP Web Dispatcher are vulnerable for

2023 MSU REU Graph DB This project is a docker-based web application to enhance analysis and mitigation, called Security System Plan Manager (SSPM) A unique list of CVE/CWE's is generated with a static analysis tool, this project will produce a comprehensive list of attack paths present and security controls recommended for the system SSPM can be used to know which NIST

Starter kit for SAP pentesting

SAP Comptes sapcom Deux types de comptes sapcom : P-User : Utilisateur public, qui peut participer à la communauté en ligne mais n'a pas accès à toutes les ressources S-User : Compte des servives utilisé par les clients et les partenaires SAP Permet notamment de télécharger des softs SAP comme le NW RFC SDK Ce type d

Vulnerability assessment for CVE-2022-22536 This repository contains a Python script that can be used to check if a SAP system is affected by CVE-2022-22536, a critical vulnerability rated with CVSSv3 Score of 100 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) This vulnerability was discovered by the Onapsis Research Labs, which closely collaborated with SAP to develop and release a p

Recent Articles

Microsoft manages a mere 51 security fixes for February update bundle
The Register • Thomas Claburn in San Francisco • 01 Jan 1970

Get our weekly newsletter Excitement this month can be found in SAP code, with critical Log4j repairs and a CISA warning

Patch Tuesday Microsoft for its February Patch Tuesday gave Windows admins just 51 fixes to apply, the smallest number of patches since the meager ration of 44 in August 2021. February tends to be a slow month for repairs because bugs left untended over the winter holidays often get dealt with in January, leaving not all that much for the following month. Perhaps more noteworthy is that there's not a single critical CVE listed in the February patch list. Fifty of the fixes are rated Important wh...