// For flags

CVE-2022-39802

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

SAP Manufacturing Execution - versiones 15.1, 15.2, 15.3, permite a un atacante explotar una comprobación insuficiente de un parámetro de petición de ruta de archivo. La ruta de archivo prevista puede ser manipulada para permitir un recorrido arbitrario de directorios en el servidor remoto. El contenido de los archivos dentro de cada directorio puede ser leído, lo que puede conllevar a una divulgación de información

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-02 CVE Reserved
  • 2022-10-11 CVE Published
  • 2022-10-16 First Exploit
  • 2024-08-03 CVE Updated
  • 2024-08-11 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Manufacturing Execution
Search vendor "Sap" for product "Manufacturing Execution"
15.1
Search vendor "Sap" for product "Manufacturing Execution" and version "15.1"
-
Affected
Sap
Search vendor "Sap"
Manufacturing Execution
Search vendor "Sap" for product "Manufacturing Execution"
15.2
Search vendor "Sap" for product "Manufacturing Execution" and version "15.2"
-
Affected
Sap
Search vendor "Sap"
Manufacturing Execution
Search vendor "Sap" for product "Manufacturing Execution"
15.3
Search vendor "Sap" for product "Manufacturing Execution" and version "15.3"
-
Affected