PT-2015-3413 · Sap · Sap Netweaver As Java
Vahagn Vardanyan
·
Published
2015-09-29
·
Updated
2025-03-07
·
CVE-2016-3976
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS Java versions 7.1 through 7.5
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot backslash) in the
fileName parameter to "CrashFileDownloadServlet". This is due to a directory traversal vulnerability. The vulnerability can be exploited by sending a specially crafted malicious GET request to the "/XXX/CrashFileDownloadServlet" endpoint with the fileName parameter set to "..".Recommendations
For SAP NetWeaver AS Java versions 7.1 through 7.5, consider disabling the CrashFileDownloadServlet until a patch is available. Restrict access to the CrashFileDownloadServlet endpoint to minimize the risk of exploitation. Avoid using the
fileName parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Java