CVE-2012-1289 — Path Traversal in SAP Netweaver

CWE-22 — Path Traversal3 documents3 sources
Severity
4.0MEDIUMNVD
EPSS
0.5%
top 34.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateMay 17

Description

Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admin/log.jsp or (4) ipc/admin/log_view.jsp in the Application Administration (com.sap.ipc.webapp.ipc) component.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

â–¶NVDsap/netweaver7.0

🔴Vulnerability Details

2
GHSA
GHSA-p6qx-67x2-357p: Multiple directory traversal vulnerabilities in SAP NetWeaver 7↗2022-05-17
â–¶
CVEList
CVE-2012-1289: Multiple directory traversal vulnerabilities in SAP NetWeaver 7↗2012-02-23
â–¶
CVE-2012-1289 — Path Traversal in SAP Netweaver | cvebase