Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

SAP Security Patch Day – October 2022

Because the SAP threat landscape is always expanding, businesses of all sizes and sectors are in danger of cyberattacks. The following report offers information on the
most recent security flaws and threats.


This month, the software provider released 16 SAP Security Notes;

The RedRays R&D helped SAP to fix the critical vulnerability in SAP Manufacturing Execution. The vulnerability exists from the 15.1.3 version (released in 2016) to the 15.4 version. 

At RedRays, you can find more information about the vulnerabilities and existing measures to protect your SAP systems, and exploits for the most critical vulnerabilities are already available in the RedRays Security Platform’s database.

SAP Security Notes Overview

On the 11th of October 2022, SAP Security Patch Day released 16 new Security Notes. 

This month’s a critical priority (CVSS 9.9/10) vulnerability category is a path traversal vulnerabilities. The vulnerability was discovered by our research and development team; and have been patched this month.

The details of the SAP vulnerability discovered by RedRays researchers are listed below.

  • 3242933 – [CVE-2022-39802][CVSS 9.9/10] File path traversal vulnerability in SAP Manufacturing Execution

Installing all SAP Security Notes is what our team strongly advises to minimize the risk of being compromised.

More to explorer

SAP Security For All

RedRays Security Platform for Penetration testers and Bug hunters

The product package is specifically created for cyber security experts who have encountered SAP while participating in bug bounty programs.

RedRays Security Platform for SAP Consultants

The product package is designed for SAP consultants conducting security assessments of SAP ERP systems. We provide essential tools and resources to help professionals in this field conduct their work effectively.

RedRays Security Platform for Enterprises

The product package is specifically optimized to cater to the needs of both small/medium and large companies who are seeking to streamline the process of organizing a comprehensive security system for ERP systems.