High severity7.5NVD Advisory· Published Feb 16, 2016· Updated May 6, 2026
CVE-2016-2389
CVE-2016-2389
Description
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/137046/SAP-MII-15.0-Directory-Traversal.htmlnvd
- seclists.org/fulldisclosure/2016/May/40nvd
- erpscan.io/advisories/erpscan-16-009-sap-xmii-directory-traversal-vulnerability/nvd
- erpscan.io/press-center/blog/sap-security-notes-february-2016-review/nvd
- www.exploit-db.com/exploits/39837/nvd
News mentions
0No linked articles in our index yet.