Junglewise Threat Intelligence

CVE-2017-12637: SAP NetWeaver Directory Traversal Vulnerability

CVE-2017-12637 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-03-19

Technologies: SAP NetWeaver, SAP Netweaver Application Server Java. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server (AS) Java 7.5 contains a directory traversal vulnerability in the UIUtilJavaScriptJS component. A remote, unauthenticated attacker can read arbitrary files on the server by using dot-dot (..) sequences in the query string.

Affected products

  • SAP NetWeaver Application Server Java 7.5

Timeline

  • 2017-08-07: disclosed: Initial NVD publication date
  • 2017-08-07: exploited: Exploitation in the wild reported as early as August 2017
  • 2017-08-28: advisory: SAP Security Note 2486657 referenced
  • 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats