The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SAP NetWeaver to its Known Exploited Vulnerabilities (KEV) catalog, urging organizations to immediately mitigate the risk. The vulnerability, identified as CVE-2017-12637, is a directory traversal flaw in SAP NetWeaver Application Server Java that allows remote attackers to read arbitrary files on affected systems. Organizations are encouraged to integrate this information into their security frameworks, such as the Stakeholder-Specific Vulnerability Categorization (SSVC) model, to better assess and respond to emerging threats. Security researchers have categorized this vulnerability under CWE-22, which refers to the improper limitation of a pathname to a restricted directory, commonly known as a ‘Path Traversal’ flaw. The vulnerability stems from improper input validation in the scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS component, allowing attackers to use directory traversal sequences (e.g., “../”) in the query string to access files outside of the intended directory. Organizations are advised to regularly consult the KEV catalog and other authoritative sources to stay informed about critical vulnerabilities and take swift action to secure their systems against emerging threats. CISA’s KEV catalog serves as a valuable resource in this effort, providing organizations with actionable intelligence to prioritize their security efforts and protect against active threats. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The KEV catalog entry, dated March 19, 2025, highlights the urgency of addressing this vulnerability, which has been observed as being actively exploited in the wild. Exploiting this vulnerability could lead to unauthorized access to sensitive information, potentially compromising the confidentiality and integrity of affected systems. CISA emphasizes using the KEV catalog as a critical input for vulnerability management prioritization.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Mar 2025 11:35:08 +0000