CVE-2016-3976
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
- Affected products
- Sap Netweaver As Java
- Sap Netweaver Application Server Java
- ≤ 7.50
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 46.6% (99th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2016-04-07
CVE-2016-3976 at NVD
4 known exploits for CVE-2016-3976
Proof-of-concept code and exploit modules indexed by Sploitus