Executive brief
SAP NetWeaver Application Server (AS) Java 7.5 contains a directory traversal vulnerability in the UIUtilJavaScriptJS component. A remote, unauthenticated attacker can read arbitrary files on the server by using dot-dot (..) sequences in the query string.
Affected products
- SAP NetWeaver Application Server Java 7.5
Timeline
- 2017-08-07: disclosed: Initial NVD publication date
- 2017-08-07: exploited: Exploitation in the wild reported as early as August 2017
- 2017-08-28: advisory: SAP Security Note 2486657 referenced
- 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog