Loading
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
Use CWE-22, Sap vendor hub and Netweaver Application Server Java product page to widen CVE-2017-12637 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-40309, CVE-2024-22127 and CVE-2024-24743 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.