CVE-2017-12637
SAP NetWeaver: Directory Traversal
As of , CVE-2017-12637 in SAP NetWeaver is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 19 March 2025
- US federal deadline
- 9 April 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.95Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: me.sap.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
- me.sap.comSAP users must have an account to log in and access the patch
What the flaw is
SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.
CISA's description
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
The CVE record's description, from mitre
- CVE published
- 7 August 2017
- Assigned by
- mitre
- CVSS
- 7.5 High (CVSS 3.1, from CISA-ADP)
- CWE-22
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
NetWeaver: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2020-6287Missing Authentication for Critical Function | SAP NetWeaver | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| CVE-2025-31324Unrestricted File Upload | SAP NetWeaver | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2016-2386SQL Injection | SAP NetWeaver | Patch this weekEPSS 0.72 | 0.72 | ||
| CVE-2016-2388Information Disclosure | SAP NetWeaver | Patch this weekEPSS 0.52 | 0.52 | ||
| CVE-2025-42999Deserialization | SAP NetWeaver | Patch this weekRansomware use | 0.14 | ||
| CVE-2021-38163Unrestricted File Upload | SAP NetWeaver | Patch soon | 0.37 | ||
| CVE-2016-3976Directory Traversal | SAP NetWeaver | Patch soon | 0.47 | ||
| CVE-2010-5326Remote Code Execution | SAP NetWeaver | Patch soon | 0.18 | ||
| CVE-2016-9563XML External Entity (XXE) | SAP NetWeaver | Patch soon | 0.24 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org