{"cvss":9.8,"datePublished":"2022-08-18","dateUpdated":"2022-08-18","description":"SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.","dueDate":"2022-09-08","id":"CVE-2022-22536","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso;  https://nvd.nist.gov/vuln/detail/CVE-2022-22536","product":"Multiple Products","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"SAP Multiple Products HTTP Request Smuggling Vulnerability","vendor":"SAP"}