CVE-2017-12637
KEVlargeCVE-2017-12637: Directory Traversal File Read in SAP NetWeaver AS Java 7.5
CISA: SAP NetWeaver Directory Traversal Vulnerability
CVE-2017-12637 is an unauthenticated directory traversal flaw (CWE-22) in the scheduler UI endpoint scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS of SAP NetWeaver Application Server Java 7.5. A remote attacker triggers it by inserting dot-dot (../) sequences into the query string of that endpoint, causing the server to read files outside the intended directory. Successful exploitation yields arbitrary file disclosure on the server (e.g., configuration files or credentials), with no authentication or user interaction required, consistent with the CVSS 3.1 score of 7.5 (High, network vector, confidentiality-only impact). Organizations running SAP NetWeaver Application Server Java 7.5 are affected, particularly internet-exposed instances such as SAP Enterprise Portal or Process Integration/Orchestration landscapes. The flaw was exploited in the wild as early as August 2017 and addressed via SAP Security Note 2486657; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and EPSS currently assigns a 95.1% probability of exploitation within 30 days (100th percentile).
What to do: Apply the fix from SAP Security Note 2486657 to affected Application Server Java 7.5 systems; where patching is not yet possible, restrict or block access to the scheduler UI path (scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS) and limit internet exposure of AS Java. Hunt for exploitation by reviewing web logs for dot-dot (../) traversal sequences in query strings targeting that endpoint, and follow CISA BOD 22-01 guidance for cloud services or the KEV required action if mitigations are unavailable.
| SAP NetWeaver Application Server Java | 7.5 (as specified in the CVE description; the CISA affected list covers SAP NetWeaver generally, and no other version ranges are provided in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
- Affected
- SAP NetWeaver
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver application server java
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N