Executive brief
SAP Manufacturing Integration and Intelligence contains insufficient file path validation that allows a privileged attacker to write files outside their intended directory using specially crafted input. A legitimate user must then access the attacker-influenced content for exploitation to succeed. Successful exploitation could compromise the confidentiality, integrity, and availability of affected systems and potentially spread to other connected components.
Technical details
The vulnerability is a path traversal flaw in SAP Manufacturing Integration and Intelligence caused by insufficient file path validation in certain functions. The attack requires an attacker with elevated privileges to inject specially crafted input, followed by a legitimate user accessing the attacker-controlled content—making it a multi-stage attack with external dependencies. An attacker can write arbitrary files outside the intended directory, potentially affecting other system components. The vulnerability has been documented by SAP under their security patching program and patches are expected to be available through SAP Security Notes.
Affected products
- SAP Manufacturing Integration and Intelligence
Timeline
- 2026-08-11: disclosed
- other: Patch Day notification date: 2026-08-11