
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
This is a fast, socket-level batch scanner for CVE-2022-22536, a critical request smuggling vulnerability in SAP Internet Communication Manager (ICM) and SAP Web Dispatcher. It tests multiple hosts in parallel for protocol desynchronization behavior.
CVE-2022-22536 is rated CVSS 10.0 and is known to be exploited in the wild (CISA KEV list).
This tool helps identify potentially vulnerable SAP systems exposed over HTTP or HTTPS.
tqdm] for progress bartqdmInstall:
pip install tqdm