← Vulnerability feed

Vulnerability record · CVE-2016-3976 · published 7 April 2016

CVE-2016-3976: SAP NetWeaver AS Java directory traversal in CrashFileDownloadServlet

Sap · Netweaver Application Server Java

SAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A remote attacker can supply a dot-dot-backslash sequence to read arbitrary files from the server. Because the servlet is reachable over the network without credentials, the flaw exposes sensitive files on the SAP host.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 47% · top 1.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
47%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication, has public exploit code, and is listed in CISA KEV with a high EPSS score, making it a high-value target for immediate remediation.

What it is

SAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A remote attacker can supply a dot-dot-backslash sequence to read arbitrary files from the server. Because the servlet is reachable over the network without credentials, the flaw exposes sensitive files on the SAP host.

Impact

An unauthenticated attacker can read arbitrary files accessible to the SAP Java process, potentially exposing configuration, credential stores, and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to CrashFileDownloadServlet with a crafted fileName parameter; the CVSS vector shows no privileges or user interaction required. No authentication is needed.

Exploitation

CVE-2016-3976 is listed in CISA KEV with a due date of 2022-05-03, and public exploit references exist (Packet Storm, Exploit-DB, Full Disclosure). EPSS shows a 30-day probability of 0.46605 (98.8th percentile), indicating high likelihood of exploitation activity.

What to do

  • Apply the SAP Security Note 2234971 update or the vendor-provided patch for NetWeaver AS Java 7.1 through 7.5.
  • If patching is not immediately possible, restrict network access to CrashFileDownloadServlet and the SAP Java HTTP/HTTPS ports to trusted management networks.
  • Validate and sanitize the fileName parameter to reject path traversal sequences, or disable the CrashFileDownloadServlet if it is not required.
  • Run the SAP Java process with least privilege and ensure it cannot read sensitive OS files outside its required directories.
  • Monitor SAP security notes and CISA KEV for updated guidance and confirm remediation status.

Detection

  • Inspect HTTP access and application logs for requests to CrashFileDownloadServlet containing '..\' or encoded traversal sequences in the fileName parameter.
  • Alert on outbound or local file reads by the SAP Java process that access paths outside expected application directories.
  • Correlate unusual file download responses from SAP NetWeaver AS Java with source IPs not normally seen in the environment.
  • Use file integrity monitoring on sensitive SAP configuration and credential files to detect unexpected read access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-3976 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3976 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed10.0CVE-2010-5326SAP NetWeaver Java Invoker Servlet unauthenticated remote code executionThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attacke…KEVEPSS 18%analysed9.8CVE-2016-2386SAP NetWeaver UDDI Server SQL InjectionThe UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command executio…KEVEPSS 72%analysed7.5CVE-2017-12637SAP NetWeaver Java directory traversal allows arbitrary file readSAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attack…KEVEPSS 95%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed5.3CVE-2016-2388SAP NetWeaver AS Java Universal Worklist information disclosureThe Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an inform…KEVEPSS 52%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2016-3976), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.