{"id":"CVE-2022-22536","vendor_project":"SAP","product":"Multiple Products","vulnerability_name":"SAP Multiple Products HTTP Request Smuggling Vulnerability","date_added":"2022-08-18","due_date":"2022-09-08","known_ransomware_use":"Unknown","short_description":"SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.","required_action":"Apply updates per vendor instructions.","cwes":"CWE-444","cvss_version":"3.1","cvss_severity":"CRITICAL","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","nvd_published":"2022-02-09","nvd_status":"Analyzed","epss":0.97945,"epss_percentile":0.99907,"cvss_score":10,"days_published_to_kev":190,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2022-22536","by":"CyberMax"}