CVE-2016-2389: Path Traversal
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2389?
CVE-2016-2389 is considered a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2016-2389?
To fix CVE-2016-2389, apply the relevant patches provided in SAP Security Note 2230978 and ensure proper input validation for the Path parameter.
Who is affected by CVE-2016-2389?
CVE-2016-2389 affects users of SAP Manufacturing Integration and Intelligence (xMII) component 15.0 on SAP NetWeaver 7.4.
What type of attack does CVE-2016-2389 enable?
CVE-2016-2389 enables directory traversal attacks that can allow remote attackers to read arbitrary files on the server.
What components are involved in CVE-2016-2389?
CVE-2016-2389 specifically involves the GetFileList function in the SAP Manufacturing Integration and Intelligence component.