CVE-2016-3976
KEV PoC ×3largeDirectory Traversal File-Read Flaw in SAP NetWeaver Application Server (Java)
CISA: SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Application Server (Java) contains a directory traversal vulnerability (CWE-22) in its CrashFileDownloadServlet. A remote attacker sends a request to the servlet with a dot-dot-backslash (..\) traversal sequence in the fileName parameter, causing the server to step outside the intended directory and return the contents of arbitrary files. Successful exploitation lets the attacker read sensitive files on the host, such as configuration or credential material, which can support further compromise; no code execution is involved. Any organization running SAP NetWeaver Application Server Java, typically large enterprises with SAP landscapes, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and EPSS assigns a 46.6% probability of exploitation in the next 30 days (99th percentile).
What to do: Apply SAP security updates for NetWeaver AS Java per vendor instructions, as required by CISA's KEV listing. Until patched, restrict network access to the CrashFileDownloadServlet endpoint from untrusted networks and review web logs for requests using dot-dot-backslash (..\) sequences in the fileName parameter. Prioritize internet-facing SAP Java instances, since exploitation is confirmed and the EPSS score indicates high near-term exploitation probability.
| SAP NetWeaver (Application Server Java, CrashFileDownloadServlet) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver application server java
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N