CVE-2016-2386 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 71.5% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-30.
Description
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 71.52% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2022-06-30 |
| Public exploit | yes |
| Published | 2016-02-16 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | SAP NetWeaver SQL Injection Vulnerability |
|---|---|
| Added | 2022-06-09 |
| Due | 2022-06-30 |
| Vendor / product | SAP / NetWeaver |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| sap | netweaver application server java |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | 2018-01-10 |
| exploit-db | SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection | 2016-05-19 |
References
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html
- http://seclists.org/fulldisclosure/2016/May/56
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/
- https://github.com/vah13/SAP_exploit
- https://www.exploit-db.com/exploits/39840/
- https://www.exploit-db.com/exploits/43495/
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html
- http://seclists.org/fulldisclosure/2016/May/56
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/
- https://github.com/vah13/SAP_exploit
- https://www.exploit-db.com/exploits/39840/
- https://www.exploit-db.com/exploits/43495/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386
→ the Explorer · watch your stack · NVD