It is rare to see vulnerabilities with the maximum CVSS score of 10 out of 10, but SAP’s February security patch bundle fixes four of them along with details of a serious vulnerability named ICMAD.
Three of the critical vulnerabilities in SAPs February Security Advisory are fixing Log4j related issues. The fourth critical vulnerability (CVE-2022-22536) affects the SAP Internet Communication Manager and also requires immediate attention.
The SAP Internet Communication Manager (ICM) is a core component of SAP NetWeaver business applications and is present in most SAP products.
A trio of vulnerabilities have been identified in the SAP ICM module by security researchers as Onapsis and the most serious CVE-2022-22536 is a HTTP request smuggling attack.
An unauthenticated attacker can exploit this vulnerability by using request smuggling and request concatenation techniques to prepend a victim’s request with arbitrary data. This allows the attacker to execute functions impersonating the victim or poison intermediary Web caches.
Onapsis have released a tool on Github to help SAP admins identify if their installation is vulnerable to ICMAD attacks.
“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”
Aim Ltd Chief Technology Officer (CTO)