Vulnerability record · CVE-2017-12637 · published 7 August 2017
CVE-2017-12637: SAP NetWeaver Java directory traversal allows arbitrary file read
Sap · Netweaver Application Server Java
SAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attacker can place a .. (dot dot) sequence in the query string to read arbitrary files from the server. The vulnerability was exploited in the wild in August 2017 and is tracked as SAP Security Note 2486657.
Description
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has confirmed in-the-wild exploitation, is in CISA KEV, and has an EPSS score above the 99th percentile.
What it is
SAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attacker can place a .. (dot dot) sequence in the query string to read arbitrary files from the server. The vulnerability was exploited in the wild in August 2017 and is tracked as SAP Security Note 2486657.
Impact
An unauthenticated remote attacker can read arbitrary files on the affected server, exposing configuration, credentials, and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
The flaw is reachable over the network via HTTP requests to the affected SAP NetWeaver Java component, with no authentication or user interaction required (CVSS AV:N/PR:N/UI:N).
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2025-03-19, and the description states it was exploited in the wild in August 2017. EPSS gives a 30-day exploitation probability of 0.95111 (99.86th percentile), indicating very high likelihood of attempted exploitation.
What to do
- Apply the fix from SAP Security Note 2486657 as soon as possible.
- If patching is not immediately possible, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
- Restrict network access to the SAP NetWeaver Java scheduler UI paths to trusted sources only.
- Monitor for and block HTTP requests containing traversal sequences such as ../ in query strings to the affected component.
Detection
- Inspect web server and SAP logs for requests to scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS containing ../ or encoded traversal sequences.
- Alert on HTTP responses returning file contents or unusual file paths from the affected endpoint.
- Correlate outbound or internal access to sensitive files with requests to the vulnerable scheduler UI path.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12637 to the Known Exploited Vulnerabilities catalog on 19 March 2025 as "SAP NetWeaver Directory Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://web.archive.org/web/20170807202056/http://www.sh0w.top/index.php/archives/7/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12637 | US Government Resource |
Track CVE-2017-12637 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12637), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.