{"cve":{"cve_id":"CVE-2022-22536","is_kev":true,"kev_date_added":"2022-08-18","kev_vendor_project":"SAP","kev_product":"Multiple Products","kev_vulnerability_name":"SAP Multiple Products HTTP Request Smuggling Vulnerability","kev_short_description":"SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.","kev_required_action":"Apply updates per vendor instructions.","kev_due_date":"2022-09-08","kev_known_ransomware":false,"kev_notes":"SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso;  https://nvd.nist.gov/vuln/detail/CVE-2022-22536","kev_cwes":["CWE-444"],"epss_score":0.97945,"epss_percentile":0.99901,"epss_as_of":"2026-06-23","description":"SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.","published_at":"2022-02-09T22:05:24Z","last_modified_at":null,"cvss_v3_score":9.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-444"],"nvd_references":["https://launchpad.support.sap.com/#/notes/3123396","https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-06-28T23:17:00.636257Z"},"effective_severity":"CRITICAL","badges":["kev","poc","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-content-server","product_name":"SAP Content Server","version_start":"7.53","version_start_inclusive":true,"version_end":"7.53","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-content-server:7.53:7.53"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"8.04","version_start_inclusive":true,"version_end":"8.04","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:8.04:8.04"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.49","version_start_inclusive":true,"version_end":"7.49","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.49:7.49"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.53","version_start_inclusive":true,"version_end":"7.53","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.53:7.53"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.77","version_start_inclusive":true,"version_end":"7.77","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.77:7.77"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.81","version_start_inclusive":true,"version_end":"7.81","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.81:7.81"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.85","version_start_inclusive":true,"version_end":"7.85","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.85:7.85"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.86","version_start_inclusive":true,"version_end":"7.86","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.86:7.86"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.87","version_start_inclusive":true,"version_end":"7.87","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.87:7.87"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"KRNL64UC 8.04","version_start_inclusive":true,"version_end":"KRNL64UC 8.04","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:KRNL64UC 8.04:KRNL64UC 8.04"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.22","version_start_inclusive":true,"version_end":"7.22","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.22:7.22"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"KERNEL 7.22","version_start_inclusive":true,"version_end":"KERNEL 7.22","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:KERNEL 7.22:KERNEL 7.22"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"KRNL64NUC 7.22","version_start_inclusive":true,"version_end":"KRNL64NUC 7.22","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:KRNL64NUC 7.22:KRNL64NUC 7.22"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-netweaver-and-abap-platform","product_name":"SAP NetWeaver and ABAP Platform","version_start":"7.22EXT","version_start_inclusive":true,"version_end":"7.22EXT","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-netweaver-and-abap-platform:7.22EXT:7.22EXT"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.53","version_start_inclusive":true,"version_end":"7.53","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.53:7.53"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.77","version_start_inclusive":true,"version_end":"7.77","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.77:7.77"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.81","version_start_inclusive":true,"version_end":"7.81","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.81:7.81"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.85","version_start_inclusive":true,"version_end":"7.85","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.85:7.85"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.22EXT","version_start_inclusive":true,"version_end":"7.22EXT","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.22EXT:7.22EXT"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.86","version_start_inclusive":true,"version_end":"7.86","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.86:7.86"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.87","version_start_inclusive":true,"version_end":"7.87","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.87:7.87"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-web-dispatcher","product_name":"SAP Web Dispatcher","version_start":"7.49","version_start_inclusive":true,"version_end":"7.49","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-web-dispatcher:7.49:7.49"}],"exploit_refs":[{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22536.yaml","title":"SAP Memory Pipes (MPI) Desynchronization","author":"pdteam","disclosed_at":null}],"news":[],"references":[{"url":"https://launchpad.support.sap.com/#/notes/3123396","source_type":"MISC","tags":[]},{"url":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2022-02-09T22:05:24Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2022-08-18T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"poc_available","at":"2026-06-24T00:29:48.638073Z","label":"Public PoC available","source":"nuclei"},{"type":"ssvc_changed","at":"2026-06-24T00:31:59.395211Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:59.395211Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:59.395211Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:59.395211Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:59.395211Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:59.395211Z","label":"CVSS score revised","source":"vulnrichment"}]}