CVE-2022-39802

HIGH

SAP Manufacturing Execution 15.1-15.3 - Path Traversal via File Path Request Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-39802. PoCs published by redrays-io.

AI-analyzed exploit summary This repository provides a detailed technical description of CVE-2022-39802, a file path traversal vulnerability in SAP Manufacturing Execution. It includes vulnerability details, affected versions, and mitigation suggestions but lacks actual exploit code.

Description

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

Exploits (1)

nomisec WRITEUP 3 stars
by redrays-io · poc
https://github.com/redrays-io/CVE-2022-39802

This repository provides a detailed technical description of CVE-2022-39802, a file path traversal vulnerability in SAP Manufacturing Execution. It includes vulnerability details, affected versions, and mitigation suggestions but lacks actual exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: SAP Manufacturing Execution Core 15.1, 15.2, 15.3
No auth needed
Prerequisites: Network access to vulnerable SAP Manufacturing Execution instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0643
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
sap/manufacturing_execution 15.1
sap/manufacturing_execution 15.2
sap/manufacturing_execution 15.3
Published Oct 11, 2022
Tracked Since Feb 18, 2026