Inconsistent interpretation of HTTP requests in SAP products - CVE-2022-22536
Published: August 4, 2023 / Updated: April 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can prepend a victim's request with arbitrary data and execute functions impersonating the victim or poison intermediary Web caches.
Successful exploitation of the vulnerability can result in full system compromise.
Affected software
SAP NetWeaver AS ABAP
SAP Content Server
SAP Web Dispatcher WEBDISP
How to mitigate CVE-2022-22536
Links to Public Exploits and PoC-codes
- Exploit #11276 - SAPGateBreaker-Exploit (SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass ACLs by desynchronizing request parsing between ICM and backend services using craf (April 4, 2025)
- Exploit #10513 - CVE-2022-22536 (SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.) (September 20, 2024)
- Exploit #9404 - SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536 () (November 7, 2023)
- Exploit #9303 - CVE-2022-22536 (SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.) (September 8, 2023)