SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-2386

SAP NetWeaver SQL Injection Vulnerability

KEVCRITICAL 9.8EPSS 71.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
71.06% probability · 99th percentile
CISA KEV
Listed 9 June 2022 · due 30 June 2022
Weakness
CWE-89
Affected
sap/netweaver application server java
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-2386

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.