Skip links

SAP Security Patch Day – October 2022

Because the SAP threat landscape is always expanding, businesses of all sizes and sectors are in danger of cyberattacks. The following report offers information on the
most recent security flaws and threats.

Summary 

This month, the software provider released 16 SAP Security Notes;

The RedRays R&D helped SAP to fix the critical vulnerability in SAP Manufacturing Execution. The vulnerability exists from the 15.1.3 version (released in 2016) to the 15.4 version. 


At RedRays, you can find more information about the vulnerabilities and existing measures to protect your SAP systems, and exploits for the most critical vulnerabilities are already available in the RedRays Security Platform’s database.

SAP Security Notes Overview

On the 11th of October 2022, SAP Security Patch Day released 16 new Security Notes. 

This month’s a critical priority (CVSS 9.9/10) vulnerability category is a path traversal vulnerabilities. The vulnerability was discovered by our research and development team; and have been patched this month.

The details of the SAP vulnerability discovered by RedRays researchers are listed below.

  • 3242933 – [CVE-2022-39802][CVSS 9.9/10] File path traversal vulnerability in SAP Manufacturing Execution

Installing all SAP Security Notes is what our team strongly advises to minimize the risk of being compromised.

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error