CVE-2016-3976highunder attackCWE-22

CVE-2016-3976

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.5epss 47%
from disclosure to weapon75 days
Published on NVDApr 7
1st PoC+75d
CISA KEV+2036d
exploitation probability
47%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

A flaw in SAP NetWeaver AS Java allows attackers to read any file on the server by using special path characters (..\) to escape the intended directory. This is dangerous because sensitive files like configuration and credentials could be exposed.

Technical detail

Directory traversal vulnerability in CrashFileDownloadServlet affecting SAP NetWeaver AS Java 7.1–7.5, exploitable via crafted ..\sequences in the fileName parameter. The vulnerability permits unauthenticated remote file access due to insufficient input validation, leading to confidentiality breach of arbitrary system files.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.