Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 27 Mar 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 19 Mar 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Wed, 19 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2017-08-07T20:00:00.000Z
Updated: 2025-03-27T02:55:31.305Z
Reserved: 2017-08-07T00:00:00.000Z
Link: CVE-2017-12637

Updated: 2025-03-27T02:48:43.285Z

Status : Undergoing Analysis
Published: 2017-08-07T20:29:01.120
Modified: 2025-03-27T03:15:12.880
Link: CVE-2017-12637

No data.