CVE-2016-3976
Beschrijving
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a .. (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
Required action: Apply updates per vendor instructions.