
Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise confidentiality, integrity, and availability.
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
What an attacker is doing here to exploit this vulnerability is abusing a Desynchronization in the way the SAP application server processes and stores requests called memory pipes.
Essentially the attacker can send a set of HTTP requests without authentication through the proxy, to the SAP server.
And it creates a Desynchronization in the responses in a way that the attacker can poison the cache Of the proxy that's in between.
The next time that a valid end user requests that URL from the system, the proxy would actually deliver the malicious payload that was modified or implemented by the attacker.
An easy way to think about this: An attacker could modify the SAP log in screen, and the next time a Valid SAP user tries to log into the system, they would be putting their credentials in a website controlled by the attacker and the attacker will be able to exfiltrate these credentials.
If an unauthenticated attacker is able to successfully exploit the ICMAD vulnerabilities, the impact to the business could be critical.
Personally, what I think the best option to verify the vulnerability is Burpsuite > checking request smuggling manually. There are limited python scripts available out in the wild but it seems to be caching the issue, not sure why.
These scripts are really nice but personally I would recommend Burpsuite > Manually verifying Request Smuggling.
https://github.com/Onapsis/onapsis_icmad_scanner/blob/master/src/ICMAD_scanner.py @Onapsis
https://github.com/antx-code/CVE-2022-22536/blob/main/CVE-2022-22536.py @antx-code
The python script is basically exploiting the vulnerability and it is not something which is scanning and telling you if it’s just vulnerable or not vulnerable.
The script sends multiple requests containing the payload which will causes “Desynchronization” on proxy server and when next request is made the script verifies the bad request response which proves the existence of the vulnerability.
sap_path you can test:
/sap/admin/public/default.html &
/sap/public/bc/ur/Login/assets/corbu/sap_logo.png
GET /sap/admin/public/default.html HTTP/1.1
Host: {{target}}
Content-Length: 82700
Connection: close