peter bassill · operator
$ cve CVE-2016-2386 JSON

CVE-2016-2386 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 71.5% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-30.

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS71.52% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2022-06-30
Public exploityes
Published2016-02-16
Last modified2026-06-17

CISA KEV

NameSAP NetWeaver SQL Injection Vulnerability
Added2022-06-09
Due2022-06-30
Vendor / productSAP / NetWeaver
Ransomware usenone reported

Affected (1)

VendorProduct
sapnetweaver application server java

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD