CVE-2022-22532
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2022-22532 is a critical vulnerability affecting SAP NetWeaver Application Server Java across multiple versions (KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53). The vulnerability allows an unauthenticated attacker to submit crafted HTTP server requests that trigger improper shared memory buffer handling (NVD, CVE).

Technical details

The vulnerability is classified as an HTTP request smuggling issue (CWE-444) with a CVSS v3.1 base score of 9.8 (CRITICAL). It can be exploited without authentication and particularly affects systems without an HTTP proxy. The vulnerability is part of a broader set of flaws known collectively as ICMAD, affecting the Internet Communication Manager (ICM) component used by many SAP applications (SecurityWeek).

Impact

Successful exploitation of this vulnerability could allow attackers to execute malicious payloads, impersonate victims, and steal logon sessions. The impact extends to potential theft of user credentials and personal information, exfiltration of sensitive data, fraudulent financial transactions, and system disruption (SecurityWeek).

Mitigation and workarounds

Organizations are strongly advised to apply the security patches released by SAP as part of their February 2022 Security Patch Day. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to implement these patches immediately. Onapsis has provided an open-source tool to identify vulnerable systems that require patching (CISA).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42945MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 12, 2025
CVE-2025-42956MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42981MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42969MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42902MEDIUM5.3
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesOct 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management