Site icon TheCyberThrone

CISA Adds 7 vulnerabilities to Known Exploited Catalog

Advertisements

The U.S. CISA added critical SAP security flaw to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

Tracked as CVE-2022-22536, with CVSS risk score of 10.0, addressed by SAP as part of its Patch Tuesday updates for February 2022.

Described as an HTTP request smuggling vulnerability, the shortcoming impacts the following product versions

Advertisements

An unauthenticated attacker can prepend a victim’s request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary web caches.

The CISA notification, is light on technical details of in-the-wild attacks associated with the vulnerabilities to avoid threat actors taking further advantage of them.

To mitigate exposure to potential threats, Federal Civilian Executive Branch agencies are mandated to apply the relevant patches by September 8, 2022

Exit mobile version