Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536 — Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise confidentiality, integrity, and availability. | Kitploit
Tools/GitHubGitHub/tess-ss/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubtess-ss/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536

SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise confidentiality, integrity, and availability.

View Repository
105114 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536

What is the vulnerability about?

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

Detailed Explanation about the attack scenario?

What an attacker is doing here to exploit this vulnerability is abusing a Desynchronization in the way the SAP application server processes and stores requests called memory pipes.

Essentially the attacker can send a set of HTTP requests without authentication through the proxy, to the SAP server.

And it creates a Desynchronization in the responses in a way that the attacker can poison the cache Of the proxy that's in between.

The next time that a valid end user requests that URL from the system, the proxy would actually deliver the malicious payload that was modified or implemented by the attacker.

An easy way to think about this: An attacker could modify the SAP log in screen, and the next time a Valid SAP user tries to log into the system, they would be putting their credentials in a website controlled by the attacker and the attacker will be able to exfiltrate these credentials.

If an unauthenticated attacker is able to successfully exploit the ICMAD vulnerabilities, the impact to the business could be critical.

How to verify the issue?

Personally, what I think the best option to verify the vulnerability is Burpsuite > checking request smuggling manually. There are limited python scripts available out in the wild but it seems to be caching the issue, not sure why.

What python scripts are avalaible, to verify?

These scripts are really nice but personally I would recommend Burpsuite > Manually verifying Request Smuggling.

https://github.com/Onapsis/onapsis_icmad_scanner/blob/master/src/ICMAD_scanner.py @Onapsis

https://github.com/antx-code/CVE-2022-22536/blob/main/CVE-2022-22536.py @antx-code

What is the python script basically doing?

The python script is basically exploiting the vulnerability and it is not something which is scanning and telling you if it’s just vulnerable or not vulnerable.

The script sends multiple requests containing the payload which will causes “Desynchronization” on proxy server and when next request is made the script verifies the bad request response which proves the existence of the vulnerability.

PROOF-OF-CONCEPT:-

sap_path you can test: /sap/admin/public/default.html & /sap/public/bc/ur/Login/assets/corbu/sap_logo.png

GET /sap/admin/public/default.html HTTP/1.1
Host: {{target}}
Content-Length: 82700
Connection: close
Download Tool