Lucene search

K
cve[email protected]CVE-2022-39802
HistoryOct 11, 2022 - 9:15 p.m.

CVE-2022-39802

2022-10-1121:15:14
CWE-22
web.nvd.nist.gov
34
9
sap
manufacturing execution
cve-2022-39802
directory traversal
information disclosure

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.3%

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

Affected configurations

NVD
Node
sapmanufacturing_executionMatch15.1
OR
sapmanufacturing_executionMatch15.2
OR
sapmanufacturing_executionMatch15.3

CNA Affected

[
  {
    "vendor": "SAP SE",
    "product": "SAP Manufacturing Execution",
    "versions": [
      {
        "version": "15.1",
        "status": "affected"
      },
      {
        "version": "15.2",
        "status": "affected"
      },
      {
        "version": "15.3",
        "status": "affected"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.3%

Related for CVE-2022-39802