CVE-2017-12637 is a directory traversal vulnerability in SAP NetWeaver Application Server Java 7.5, specifically within the scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS component. This flaw allows remote attackers to read arbitrary files by manipulating the query string with a "..", leading to potential unauthorized information disclosure. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network without authentication or user interaction. It has been actively exploited in the wild since August 2017, as confirmed by its inclusion in CISA's KEV catalog. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and the vulnerability has garnered significant community discussion, indicating its continued relevance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.50CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.