Loading
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
Use CWE-22, Sap vendor hub and Netweaver Application Server Java product page to widen CVE-2016-3976 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-40309, CVE-2024-22127 and CVE-2024-24743 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.