보안뉴스 아카이브
긴급도 65/100 심각도 미평가 · 미평가 악용확률 98.8% CISA KEV · 2021-11-03

CVE-2016-3976

CISA 기관 조치 기한: 2022-05-03

SAP NetWeaver

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC

NVD 상세 ↗   참고 링크 ↗

← 취약점 목록