SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2022-10-11T00:00:00

Updated: 2024-08-03T12:07:42.684Z

Reserved: 2022-09-02T00:00:00

Link: CVE-2022-39802

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-11T21:15:14.833

Modified: 2022-10-28T20:49:03.430

Link: CVE-2022-39802

cve-icon Redhat

No data.