CVE-2016-2386

CRITICAL KEV

SAP NetWeaver Application Server Java 7.40 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-2386 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 9, 2022. EIP tracks 4 public exploits from researchers including Vahagn Vardanyan, ERPScan, murataydemir.

AI-analyzed exploit summary This exploit demonstrates a time-based SQL injection (CVE-2016-2386) in SAP NetWeaver AS Java UDDI 7.11-7.50, leveraging information disclosure (CVE-2016-2388) to retrieve administrator credentials. It uses a SOAP request to extract password hashes via blind SQLi.

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Exploits (4)

exploitdb WORKING POC
by Vahagn Vardanyan · pythonwebappsmultiple
https://www.exploit-db.com/exploits/43495

This exploit demonstrates a time-based SQL injection (CVE-2016-2386) in SAP NetWeaver AS Java UDDI 7.11-7.50, leveraging information disclosure (CVE-2016-2388) to retrieve administrator credentials. It uses a SOAP request to extract password hashes via blind SQLi.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: SAP NetWeaver AS Java UDDI 7.11-7.50
No auth needed
Prerequisites: Network access to SAP NetWeaver AS Java UDDI service · SOAP endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by ERPScan · textwebappsxml
https://www.exploit-db.com/exploits/39840

This exploit demonstrates an SQL injection vulnerability in SAP NetWeaver AS JAVA 7.1-7.5 via a crafted SOAP request to the UDDISecurityImplBean endpoint. The PoC injects a malicious SQL query into the permissionId parameter to extract data from the BC_UDV3_EL8EM_KEY table.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SAP NetWeaver AS JAVA 7.1 - 7.5
No auth needed
Prerequisites: Network access to the SAP NetWeaver AS JAVA server · SOAP endpoint /XXX/UDDISecurityImplBean must be exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by murataydemir · infoleak
https://github.com/murataydemir/CVE-2016-2386

The repository contains functional exploit code demonstrating SQL injection in SAP NetWeaver AS JAVA UDDI Component via crafted SOAP requests. The payloads target the `deletePermissionById` method to extract sensitive data.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SAP NetWeaver AS JAVA UDDI Component
No auth needed
Prerequisites: Network access to the vulnerable SAP NetWeaver AS JAVA UDDI endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/vah13/SAP_exploit

This repository contains a functional Python script demonstrating a time-based SQL injection (CVE-2016-2386) in SAP NetWeaver AS Java UDDI 7.11-7.50. The exploit leverages a crafted SOAP request to extract sensitive data, including administrator password hashes, and includes detailed technical explanations and payload examples.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: SAP NetWeaver AS Java UDDI 7.11-7.50
No auth needed
Prerequisites: Network access to the SAP NetWeaver AS Java UDDI service · Python environment to run the script
devstral-2 · analyzed Feb 25, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/39840/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/vah13/SAP_exploit
Broken Link, Third Party Advisory x_refsource_misc
https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43495/
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/May/56

Scores

CVSS v3 9.8
EPSS 0.7086
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-06-09
VulnCheck KEV 2022-06-09
InTheWild.io 2022-06-09
ENISA EUVD EUVD-2016-3470
CWE
CWE-89
Status published
Products (1)
sap/netweaver_application_server_java 7.40
Published Feb 16, 2016
KEV Added Jun 09, 2022
Tracked Since Feb 18, 2026