Vulnerability Name: | CVE-2022-39802 (CCN-238274) | ||||||||||||
Assigned: | 2022-10-11 | ||||||||||||
Published: | 2022-10-11 | ||||||||||||
Updated: | 2022-10-28 | ||||||||||||
Summary: | SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
8.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-22 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-39802 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/168716/SAP-Manufacturing-Execution-Core-15.3-Path-Traversal.html Source: XF Type: UNKNOWN sap-cve202239802-dir-traversal(238274) Source: CCN Type: SAP Web site SAP Support Note 3242933 Source: MISC Type: Permissions Required, Vendor Advisory https://launchpad.support.sap.com/#/notes/3242933 Source: CCN Type: Packet Storm Security [10-17-2022] SAP Manufacturing Execution Core 15.3 Path Traversal Source: CCN Type: SAP Patch Day Blog SAP Patch Day Blog Source: MISC Type: Vendor Advisory https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |