← Back to browse · API

CVE-2017-12637

Severity
HIGH
CVSS
7.5
EPSS
0.94557
Risk score
58.09
CISA KEV
Yes
PoC
No
Published
2017-08-07
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2017-4176, GHSA-5P56-56JF-WFV2
Products
SAP:NetWeaver, n/a:n/a n/a
Sources
cisa.gov CVE-2017-12637
euvd EUVD-2017-4176

Description

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

References