{"cveID":"CVE-2017-12637","vendorProject":"SAP","product":"NetWeaver","vulnerabilityName":"SAP NetWeaver Directory Traversal Vulnerability","dateAdded":"2025-03-19","shortDescription":"SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-04-09","knownRansomwareCampaignUse":"Unknown","notes":"SAP users must have an account to log in and access the patch: https://me.sap.com/notes/3476549 ; https://nvd.nist.gov/vuln/detail/CVE-2017-12637","cwes":["CWE-22"],"year":2017,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2017-12637","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"dir_traversal","comments":"By exploiting this vulnerability in SAP Netweaver Java, the attacker can inject directory traversal commands, allowing for navigation of the file system beyond intended access. This can additionally lead to the discovery of password stores, as well as information about the host system, providing information that can be used in further attacks.","references":["https://onapsis.com/blog/active-exploitation-cve-2017-12637-sap/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-12637","technique":"T1083","technique_name_at_mapping":"File and Directory Discovery","mapping_type":"primary_impact","capability_group":"dir_traversal","comments":"By exploiting this vulnerability in SAP Netweaver Java, the attacker can inject directory traversal commands, allowing for navigation of the file system beyond intended access. This can additionally lead to the discovery of password stores, as well as information about the host system, providing information that can be used in further attacks.","references":["https://onapsis.com/blog/active-exploitation-cve-2017-12637-sap/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-12637","technique":"T1555","technique_name_at_mapping":"Credentials from Password Stores","mapping_type":"secondary_impact","capability_group":"dir_traversal","comments":"By exploiting this vulnerability in SAP Netweaver Java, the attacker can inject directory traversal commands, allowing for navigation of the file system beyond intended access. This can additionally lead to the discovery of password stores, as well as information about the host system, providing information that can be used in further attacks.","references":["https://onapsis.com/blog/active-exploitation-cve-2017-12637-sap/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-12637","technique":"T1592","technique_name_at_mapping":"Gather Victim Host Information","mapping_type":"secondary_impact","capability_group":"dir_traversal","comments":"By exploiting this vulnerability in SAP Netweaver Java, the attacker can inject directory traversal commands, allowing for navigation of the file system beyond intended access. This can additionally lead to the discovery of password stores, as well as information about the host system, providing information that can be used in further attacks.","references":["https://onapsis.com/blog/active-exploitation-cve-2017-12637-sap/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1083","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"File and Directory Discovery","name_at_mapping":"File and Directory Discovery","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":24,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1555","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Credentials from Password Stores","name_at_mapping":"Credentials from Password Stores","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":8,"has_detection_strategy":true},{"id":"T1592","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Gather Victim Host Information","name_at_mapping":"Gather Victim Host Information","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}