CVE-2017-12637
SAP NetWeaver
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
- CVSS
- 7.5
- EPSS
- 94.6% 99.8% percentile
- CISA KEV
- Listed
- Published
- 2017.08.08