← Vulnerability feed

Vulnerability record · CVE-2017-12637 · published 7 August 2017

CVE-2017-12637: SAP NetWeaver Java directory traversal allows arbitrary file read

Sap · Netweaver Application Server Java

SAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attacker can place a .. (dot dot) sequence in the query string to read arbitrary files from the server. The vulnerability was exploited in the wild in August 2017 and is tracked as SAP Security Note 2486657.

7.5 CVSS 3.1 High CISA KEV since 19 Mar 2025 EPSS 95% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication, has confirmed in-the-wild exploitation, is in CISA KEV, and has an EPSS score above the 99th percentile.

What it is

SAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attacker can place a .. (dot dot) sequence in the query string to read arbitrary files from the server. The vulnerability was exploited in the wild in August 2017 and is tracked as SAP Security Note 2486657.

Impact

An unauthenticated remote attacker can read arbitrary files on the affected server, exposing configuration, credentials, and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

The flaw is reachable over the network via HTTP requests to the affected SAP NetWeaver Java component, with no authentication or user interaction required (CVSS AV:N/PR:N/UI:N).

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2025-03-19, and the description states it was exploited in the wild in August 2017. EPSS gives a 30-day exploitation probability of 0.95111 (99.86th percentile), indicating very high likelihood of attempted exploitation.

What to do

  • Apply the fix from SAP Security Note 2486657 as soon as possible.
  • If patching is not immediately possible, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
  • Restrict network access to the SAP NetWeaver Java scheduler UI paths to trusted sources only.
  • Monitor for and block HTTP requests containing traversal sequences such as ../ in query strings to the affected component.

Detection

  • Inspect web server and SAP logs for requests to scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS containing ../ or encoded traversal sequences.
  • Alert on HTTP responses returning file contents or unusual file paths from the affected endpoint.
  • Correlate outbound or internal access to sensitive files with requests to the vulnerable scheduler UI path.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12637 to the Known Exploited Vulnerabilities catalog on 19 March 2025 as "SAP NetWeaver Directory Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12637 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed10.0CVE-2010-5326SAP NetWeaver Java Invoker Servlet unauthenticated remote code executionThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attacke…KEVEPSS 18%analysed9.8CVE-2016-2386SAP NetWeaver UDDI Server SQL InjectionThe UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command executio…KEVEPSS 72%analysed7.5CVE-2016-3976SAP NetWeaver AS Java directory traversal in CrashFileDownloadServletSAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A re…KEVEPSS 47%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed5.3CVE-2016-2388SAP NetWeaver AS Java Universal Worklist information disclosureThe Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an inform…KEVEPSS 52%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2017-12637), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.