CVE-2016-3976
CISA 기관 조치 기한: 2022-05-03
SAP NetWeaver
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC
- Exploit-DB: EDB-39996 ↗