CVE-2016-3976
published 2016-04-07CVE-2016-3976: Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the…
PriorityP183high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
46.61%
98.7th percentile
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | 7.10 – 7.50 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET requests to CrashFileDownloadServlet containing dot-dot-backslash (..\) sequences in the fileName parameter, indicating directory traversal attempts. ↗
- →No authentication is required to exploit this vulnerability; alert on any unauthenticated requests to CrashFileDownloadServlet from external/internet-facing sources. ↗
- ·Other versions beyond 7.1–7.5 may also be affected and should be assessed, as only this range was confirmed tested. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
SAP NetWeaver Directory Traversal Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2016-3976 [HIGH] CWE-22 SAP NetWeaver Directory Traversal Vulnerability
Vulnerability: SAP NetWeaver Directory Traversal Vulnerability
Affected: SAP NetWeaver
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-3976
Remediation Due Date: 2022-05-03
VulDB
SAP Netweaver Java AS 7.4 CrashFileDownloadServlet path traversal (ID 2234971 / EDB-39996)
vuldb·2026-04-23·CVSS 7.5
CVE-2016-3976 [HIGH] SAP Netweaver Java AS 7.4 CrashFileDownloadServlet path traversal (ID 2234971 / EDB-39996)
A vulnerability labeled as critical has been found in SAP Netweaver Java AS 7.4. The affected element is an unknown function of the component CrashFileDownloadServlet. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2016-3976. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
GHSA-jvxp-2488-w24g: Directory traversal vulnerability in SAP NetWeaver AS Java 7
ghsa_unreviewed·2022-04-30
CVE-2016-3976 [HIGH] CWE-22 GHSA-jvxp-2488-w24g: Directory traversal vulnerability in SAP NetWeaver AS Java 7
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
VulnCheck
SAP NetWeaver Directory Traversal Vulnerability
vulncheck·2016·CVSS 7.5
CVE-2016-3976 [HIGH] CWE-22 SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
Affected: SAP NetWeaver
Required Action: Apply updates per vendor instructions.
Exploitation References: https://digital.nhs.uk/cyber-alerts/2021/cc-3815; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.csoonline.com/article/3674119/most-common-sap-vulnerabilities-attackers-try-to-exploit.html
Remediation Due: 2022-05-03
No detection rules found.
http://packetstormsecurity.com/files/137528/SAP-NetWeaver-AS-JAVA-7.5-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2016/Jun/40https://erpscan.io/advisories/erpscan-16-012/https://erpscan.io/press-center/blog/sap-security-notes-march-2016-review/https://launchpad.support.sap.com/#/notes/2234971https://www.exploit-db.com/exploits/39996/http://packetstormsecurity.com/files/137528/SAP-NetWeaver-AS-JAVA-7.5-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2016/Jun/40https://erpscan.io/advisories/erpscan-16-012/https://erpscan.io/press-center/blog/sap-security-notes-march-2016-review/https://launchpad.support.sap.com/#/notes/2234971https://www.exploit-db.com/exploits/39996/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3976
2016-04-07
Published
2021-11-03
Added to CISA KEV
Exploited in the wild