Advertisement
Top
image credit: Adobe Stock

SAP Patches Critical Vulnerabilities in Commerce, Manufacturing Execution Products

October 12, 2022

The most severe of these issues is CVE-2022-39802 (CVSS score of 9.9), which is described as a file path traversal in Manufacturing Execution. The bug impacts Work Instruction Viewer and Visual Test and Repair, two plugins for displaying work instructions and models.

“The URL to request this information included a file path parameter that could be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory could be read in the user context of the OS user executing the NetWeaver process or service,” enterprise application protection firm Onapsis explains.

Read More on Security Week