S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-12637 Scanner

CVE-2017-12637 scanner - Directory Traversal vulnerability in SAP NetWeaver Application Server

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-12637
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SAP NetWeaver Application Server Java 7.5 is a platform that is widely used by businesses to manage their enterprise resource planning (ERP) and customer relationship management (CRM) applications. This software enables organizations to manage their business processes effectively and efficiently. It is also used for managing supply chain operations like procurement, logistics, and inventory management. This application server is designed to provide a centralized infrastructure for running different applications and services on top of it.

The vulnerability code CVE-2017-12637 was detected in SAP NetWeaver Application Server Java 7.5. This vulnerability is caused by a directory traversal flaw in the UIUtilJavaScriptJS located in the scheduler/ui/js/ffffffffbca41eb4 folder. This flaw allows hackers to read arbitrary files by exploiting the ".." character in the query string. Hackers can use this flaw to access confidential data like usernames, passwords, financial records, and other sensitive information stored in the server.

When hackers exploit this vulnerability, it can lead to a data breach, causing serious harm to an organization. A data breach can cause financial losses, damage to the company's reputation, lawsuits, and penalties. The sensitive data accessed by hackers can be sold to competitors, used for identity theft, or sold on the dark web, making it difficult to trace and recover.

Thanks to the pro features of the s4e.io platform, businesses can quickly and easily learn about vulnerabilities in their digital assets. The s4e.io platform provides comprehensive tools for scanning, monitoring, and securing digital assets. It also provides timely alerts on new vulnerabilities and patches, enabling businesses to stay ahead of potential threats. With s4e.io, businesses can take proactive measures to safeguard their digital assets against cyber-attacks.

 

REFERENCES

Solution Advice

To protect their organization against this vulnerability, companies should take the following precautions:

  • Apply all available security patches as soon as they are released.
  • Restrict access to the application server to authorized personnel only.
  • Implement a strong password policy that ensures that passwords are changed regularly, are complex, and not shared among employees.
  • Use firewalls, intrusion detection systems, and other security software to monitor and prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.