CVE-2022-22536 - CVE House
Back to Database
Status published Unknown CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java,...

Vulnerability Description

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22536

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server
Vulnerable Versions:
KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, KRNL64NUC 7.22

Timeline

Official Publish: February 9th, 2022
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)