S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-2389 Scanner

CVE-2016-2389 scanner - Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence (xMII) component for SAP NetWeaver

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-2389
7.5
CVSS

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SAP Manufacturing Integration and Intelligence (xMII) component for SAP NetWeaver is a software tool used in manufacturing plants to oversee and streamline plant processes. It acts as a real-time data management system to optimize production and inventory levels. xMII also facilitates the integration of machine hardware and software with the plant's enterprise resource planning (ERP) systems. 

One vulnerability that the xMII component is susceptible to is the directory traversal vulnerability, identified by the code CVE-2016-2389. This vulnerability allows malicious actors to input double dots (..) into the Path parameter of the /Catalog API, thus granting them access to arbitrary files in the system. This can expose sensitive data to unauthorized access and possibly lead to system crashes or downtime.

The exploitation of this vulnerability can result in a range of negative consequences. Attackers can use it to extract confidential data, including intellectual property, trade secrets, and personal customer information, leading to reputation damage or legal consequences. The attack can also result in the manipulation or destruction of files, leading to lost productivity and revenue.

Fortunately, with the help of the s4e.io platform, users can quickly and easily discover vulnerabilities in their digital assets. The professional features offered by the platform, such as security assessments and vulnerability scans, provide users with a comprehensive and detailed analysis of potential security risks. This allows anyone to take preemptive measures to protect their digital systems from cyber-attacks and stay ahead of the curve.

 

REFERENCES

Solution Advice

To protect against the directory traversal vulnerability in xMII, users must take the following precautions:

  • Keep the software up-to-date with the latest security patches.
  • Use a web application firewall (WAF) to block malicious input characters.
  • Implement access controls and authentication mechanisms to restrict unauthorized access to sensitive data.
  • Regularly monitor system logs for unusual activity.
  • Conduct regular penetration testing to detect vulnerabilities that may have been missed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-2389 scanner - Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence (xMII) component for SAP NetWeaver | S4E