CVE-2016-3976
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in SAP NetWeaver AS Java allows attackers to read any file on the server by using special path characters (..\) to escape the intended directory. This is dangerous because sensitive files like configuration and credentials could be exposed.
Directory traversal vulnerability in CrashFileDownloadServlet affecting SAP NetWeaver AS Java 7.1–7.5, exploitable via crafted ..\sequences in the fileName parameter. The vulnerability permits unauthenticated remote file access due to insufficient input validation, leading to confidentiality breach of arbitrary system files.
The full analysis of this CVE is available in Portuguese →