CVE-2016-1910

MEDIUM

SAP NetWeaver 7.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

Exploits (1)

exploitdb WORKING POC
by Vahagn Vardanyan · pythonwebappsmultiple
https://www.exploit-db.com/exploits/43495

Scores

CVSS v3 5.3
EPSS 0.1258
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
sap/netweaver 7.40
Published Jan 15, 2016
Tracked Since Feb 18, 2026