vulnerability

SAP NetWeaver AS JAVA CVE-2022-22533: Improper Error Handling of Smuggled HTTP Requests

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
2022-02-08
Added
2022-04-07
Modified
2022-11-23

Description

SAP NetWeaver AS JAVA, versions - 7.22, 7.49, 7.53, due to improper error handling an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer, which could result in system shutdown rendering the system unavailable.

Solution

sap-netweaver-as-java-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.