ID:10513 - Exploit for Inconsistent interpretation of HTTP requests in SAP products - CVE-2022-22536
Published: September 20, 2024
SAP NetWeaver AS ABAP
SAP NetWeaver AS JAVA
SAP Content Server
SAP Web Dispatcher WEBDISP
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can prepend a victim's request with arbitrary data and execute functions impersonating the victim or poison intermediary Web caches.
Successful exploitation of the vulnerability can result in full system compromise.