Critical Vulnerability SAP ICM Could Lead to Full System Takeover
ID: 41c8ac57-645d-515f-b97b-6e56977fd4bd
STIX ID: report--41c8ac57-645d-515f-b97b-6e56977fd4bd
Feed Name: Arctic Wolf Blog
This advisory details three "ICMAD" vulnerabilities in SAP's Internet Communication Manager, with CVE-2022-22536 rated CVSS 10.0 and able to enable unauthenticated full system takeover via HTTP request smuggling under specific proxy configurations; CVE-2022-22532 and CVE-2022-22533 impact SAP AS Java and could lead to remote code execution under complex conditions or denial-of-service. Arctic Wolf recommends immediate patching of affected SAP Web Dispatcher, NetWeaver/ABAP, and Content Server versions, prioritizing internet-facing instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
