ZeroHour

CVE-2016-3976

KEV PoC ×3large

Directory Traversal File-Read Flaw in SAP NetWeaver Application Server (Java)

CISA: SAP NetWeaver Directory Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
47%p99
Published
()
KEV added
AI analysis

SAP NetWeaver Application Server (Java) contains a directory traversal vulnerability (CWE-22) in its CrashFileDownloadServlet. A remote attacker sends a request to the servlet with a dot-dot-backslash (..\) traversal sequence in the fileName parameter, causing the server to step outside the intended directory and return the contents of arbitrary files. Successful exploitation lets the attacker read sensitive files on the host, such as configuration or credential material, which can support further compromise; no code execution is involved. Any organization running SAP NetWeaver Application Server Java, typically large enterprises with SAP landscapes, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and EPSS assigns a 46.6% probability of exploitation in the next 30 days (99th percentile).

What to do: Apply SAP security updates for NetWeaver AS Java per vendor instructions, as required by CISA's KEV listing. Until patched, restrict network access to the CrashFileDownloadServlet endpoint from untrusted networks and review web logs for requests using dot-dot-backslash (..\) sequences in the fileName parameter. Prioritize internet-facing SAP Java instances, since exploitation is confirmed and the EPSS score indicates high near-term exploitation probability.

Affected
SAP NetWeaver (Application Server Java, CrashFileDownloadServlet)
Estimated exposure
largetens of thousands of SAP NetWeaver AS Java installations worldwide, with thousands plausibly internet-exposed (estimate) — SAP NetWeaver is a core platform deployed across most large enterprises, and public internet scans have historically shown thousands of exposed SAP Java application server instances; exact counts are not present in the source data, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sap
Products
netweaver application server java
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news