CVE-2016-2386

CRITICAL KEV

SAP Netweaver Application Server Java - SQL Injection

Title source: rule

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Exploits (4)

exploitdb WORKING POC
by Vahagn Vardanyan · pythonwebappsmultiple
https://www.exploit-db.com/exploits/43495
exploitdb WORKING POC
by ERPScan · textwebappsxml
https://www.exploit-db.com/exploits/39840
nomisec WORKING POC 2 stars
by murataydemir · infoleak
https://github.com/murataydemir/CVE-2016-2386
vulncheck_xdb WORKING POC
remote
https://github.com/vah13/SAP_exploit

Scores

CVSS v3 9.8
EPSS 0.4446
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-06-09
VulnCheck KEV 2022-06-09
InTheWild.io 2022-06-09
ENISA EUVD EUVD-2016-3470
CWE
CWE-89
Status published
Products (1)
sap/netweaver_application_server_java 7.40
Published Feb 16, 2016
KEV Added Jun 09, 2022
Tracked Since Feb 18, 2026