peter bassill · operator
$ cve CVE-2016-2389 JSON

CVE-2016-2389 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 41.5% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS41.45% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2016-02-16
Last modified2026-06-17

Affected (1)

VendorProduct
sapnetweaver

Public exploits

SourceTitleDate
exploit-dbSAP xMII 15.0 - Directory Traversal2016-05-17

References

→ the Explorer  ·  watch your stack  ·  NVD