VulnerabilityAnalyzed
CVE-2016-2386
SAP NetWeaver SQL Injection Vulnerability
KEVCRITICAL 9.8EPSS 71.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 71.06% probability · 99th percentile
- CISA KEV
- Listed 9 June 2022 · due 30 June 2022
- Weakness
- CWE-89
- Affected
- sap/netweaver application server java
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-2386
References
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/May/56Exploit, Mailing List, Third Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/Broken Link, Third Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/Broken Link, Third Party Advisory
- https://github.com/vah13/SAP_exploitExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/39840/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43495/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/May/56Exploit, Mailing List, Third Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/Broken Link, Third Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/Broken Link, Third Party Advisory
- https://github.com/vah13/SAP_exploitExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/39840/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43495/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.