CVE-2016-2389
HIGH EXPLOITED NUCLEISAP NetWeaver xMII 15.0 - Directory Traversal via GetFileList Path Parameter
Title source: llmExploitation Summary
CVE-2016-2389 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including ERPScan. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in SAP xMII 15.0, allowing an attacker to read arbitrary files from the server via the GetFileList function. The PoC uses a crafted GET request to access sensitive files like /etc/passwd.
Description
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in SAP xMII 15.0, allowing an attacker to read arbitrary files from the server via the GetFileList function. The PoC uses a crafted GET request to access sensitive files like /etc/passwd.
Nuclei Templates (1)
http.favicon.hash:-266008933 || cpe:"cpe:2.3:a:sap:netweaver"
icon_hash=-266008933
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N