Skip to content
COOEY

EXPOSURES › CVE-2016-3976

CVE-2016-3976

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-3976 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

SAP NetWeaver's CrashFileDownloadServlet allowed remote attackers to read arbitrary files via directory traversal.

A directory traversal flaw in SAP NetWeaver's CrashFileDownloadServlet let attackers read files from the server's filesystem. DIBs must patch SAP NetWeaver immediately, as this flaw was actively exploited in the wild and could expose sensitive data or serve as a foothold for further compromise.

Shame score — A directory traversal vulnerability in a widely deployed enterprise platform was actively exploited in the wild, indicating a failure to patch known or easily discoverable flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are CVE databases or unrelated vendor advisories.
cooey ↗ neutral +0.00
Neutral; NVD describes the vulnerability without sentiment.
"SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files."
recentbreaches.com ↗ neutral +0.00
Neutral; unrelated breach tracker page.
vulnpedia.com ↗ neutral +0.00
Neutral; vulnerability reference site.
www.cvefind.com ↗ neutral +0.00
Neutral; CVE database site.
NVD ↗ neutral +0.00
Neutral; NVD page unrelated to CVE-2016-3976.
www.dell.com ↗ neutral +0.00
Neutral; Dell security advisory unrelated to SAP.
Neutral; Cisco security advisory unrelated to SAP.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized