Impact
SAP Manufacturing Integration and Intelligence contains an insufficient file path validation flaw that enables a privileged attacker to create paths that escape the intended working directory. Because the attack requires a legitimate user to subsequently access the attacker‑influenced content, successful exploitation can result in malicious files being written to sensitive locations, potentially corrupting or replacing critical data and impacting downstream systems. The vulnerability is a classic path traversal (CWE‑22).
Affected Systems
This flaw affects installations of SAP Manufacturing Integration and Intelligence, as documented by SAP SE. The vulnerability is specifically present in the versions prior to any patch that addresses the noted file‑path validation issue, though exact version details are not provided.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity rating. The EPSS score is not available, so the current estimate of exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The attack path requires privileged access to the SAP application and subsequent use by a legitimate user; thus, direct remote exploitation is unlikely without a stored, attacker‑controlled file being accessed by a user.
OpenCVE Enrichment