ZeroHour

CVE-2017-12637

KEVlarge

CVE-2017-12637: Directory Traversal File Read in SAP NetWeaver AS Java 7.5

CISA: SAP NetWeaver Directory Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2017-12637 is an unauthenticated directory traversal flaw (CWE-22) in the scheduler UI endpoint scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS of SAP NetWeaver Application Server Java 7.5. A remote attacker triggers it by inserting dot-dot (../) sequences into the query string of that endpoint, causing the server to read files outside the intended directory. Successful exploitation yields arbitrary file disclosure on the server (e.g., configuration files or credentials), with no authentication or user interaction required, consistent with the CVSS 3.1 score of 7.5 (High, network vector, confidentiality-only impact). Organizations running SAP NetWeaver Application Server Java 7.5 are affected, particularly internet-exposed instances such as SAP Enterprise Portal or Process Integration/Orchestration landscapes. The flaw was exploited in the wild as early as August 2017 and addressed via SAP Security Note 2486657; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and EPSS currently assigns a 95.1% probability of exploitation within 30 days (100th percentile).

What to do: Apply the fix from SAP Security Note 2486657 to affected Application Server Java 7.5 systems; where patching is not yet possible, restrict or block access to the scheduler UI path (scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS) and limit internet exposure of AS Java. Hunt for exploitation by reviewing web logs for dot-dot (../) traversal sequences in query strings targeting that endpoint, and follow CISA BOD 22-01 guidance for cloud services or the KEV required action if mitigations are unavailable.

Affected
SAP NetWeaver Application Server Java7.5 (as specified in the CVE description; the CISA affected list covers SAP NetWeaver generally, and no other version ranges are provided in the data)
Estimated exposure
largetens of thousands of SAP AS Java deployments worldwide, with a likely smaller subset (thousands) directly exposed to the internet — SAP NetWeaver Application Server Java underpins widely deployed components such as Enterprise Portal and PI/PO across SAP's large enterprise customer base, and public internet scans have historically shown thousands of exposed NetWeaver AS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sap
Products
netweaver application server java
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news