Junglewise Threat Intelligence

CVE-2016-3976: SAP NetWeaver Directory Traversal Vulnerability

CVE-2016-3976 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: SAP NetWeaver AS Java (SERVERCORE), SAP NetWeaver. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server Java contains a directory traversal vulnerability in the CrashFileDownloadServlet. Remote attackers can exploit this by using dot-dot-backslash (..\\) sequences in the fileName parameter to read arbitrary files from the server.

Affected products

  • SAP NetWeaver AS Java 7.1 through 7.5

Timeline

  • 2016-03-08: advisory: SAP Security Note 2234971 released
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date

Related threats