Vulnerability record · CVE-2016-3976 · published 7 April 2016
CVE-2016-3976: SAP NetWeaver AS Java directory traversal in CrashFileDownloadServlet
Sap · Netweaver Application Server Java
SAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A remote attacker can supply a dot-dot-backslash sequence to read arbitrary files from the server. Because the servlet is reachable over the network without credentials, the flaw exposes sensitive files on the SAP host.
Description
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has public exploit code, and is listed in CISA KEV with a high EPSS score, making it a high-value target for immediate remediation.
What it is
SAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A remote attacker can supply a dot-dot-backslash sequence to read arbitrary files from the server. Because the servlet is reachable over the network without credentials, the flaw exposes sensitive files on the SAP host.
Impact
An unauthenticated attacker can read arbitrary files accessible to the SAP Java process, potentially exposing configuration, credential stores, and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to CrashFileDownloadServlet with a crafted fileName parameter; the CVSS vector shows no privileges or user interaction required. No authentication is needed.
Exploitation
CVE-2016-3976 is listed in CISA KEV with a due date of 2022-05-03, and public exploit references exist (Packet Storm, Exploit-DB, Full Disclosure). EPSS shows a 30-day probability of 0.46605 (98.8th percentile), indicating high likelihood of exploitation activity.
What to do
- Apply the SAP Security Note 2234971 update or the vendor-provided patch for NetWeaver AS Java 7.1 through 7.5.
- If patching is not immediately possible, restrict network access to CrashFileDownloadServlet and the SAP Java HTTP/HTTPS ports to trusted management networks.
- Validate and sanitize the fileName parameter to reject path traversal sequences, or disable the CrashFileDownloadServlet if it is not required.
- Run the SAP Java process with least privilege and ensure it cannot read sensitive OS files outside its required directories.
- Monitor SAP security notes and CISA KEV for updated guidance and confirm remediation status.
Detection
- Inspect HTTP access and application logs for requests to CrashFileDownloadServlet containing '..\' or encoded traversal sequences in the fileName parameter.
- Alert on outbound or local file reads by the SAP Java process that access paths outside expected application directories.
- Correlate unusual file download responses from SAP NetWeaver AS Java with source IPs not normally seen in the environment.
- Use file integrity monitoring on sensitive SAP configuration and credential files to detect unexpected read access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-3976 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3976 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3976), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.