vulnerability

SAP NetWeaver AS JAVA CVE-2022-22533: Improper Error Handling of Smuggled HTTP Requests

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 8, 2022
Added
Apr 7, 2022
Modified
Nov 23, 2022

Description

SAP NetWeaver AS JAVA, versions - 7.22, 7.49, 7.53, due to improper error handling an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer, which could result in system shutdown rendering the system unavailable.

Solution

sap-netweaver-as-java-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.