Skip links

SAP Security Patch Day – October 2022

Because the SAP threat landscape is always expanding, businesses of all sizes and sectors are in danger of cyberattacks. The following report offers information on the
most recent security flaws and threats.

Summary 

This month, the software provider released 16 SAP Security Notes;

The RedRays R&D helped SAP to fix the critical vulnerability in SAP Manufacturing Execution. The vulnerability exists from the 15.1.3 version (released in 2016) to the 15.4 version. 


At RedRays, you can find more information about the vulnerabilities and existing measures to protect your SAP systems, and exploits for the most critical vulnerabilities are already available in the RedRays Security Platform’s database.

SAP Security Notes Overview

On the 11th of October 2022, SAP Security Patch Day released 16 new Security Notes. 

This month’s a critical priority (CVSS 9.9/10) vulnerability category is a path traversal vulnerabilities. The vulnerability was discovered by our research and development team; and have been patched this month.

The details of the SAP vulnerability discovered by RedRays researchers are listed below.

  • 3242933 – [CVE-2022-39802][CVSS 9.9/10] File path traversal vulnerability in SAP Manufacturing Execution

Installing all SAP Security Notes is what our team strongly advises to minimize the risk of being compromised.

SAP Security platform overview

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,