CVE-2016-2388
MEDIUM KEVSAP Netweaver Application Server Java < 7.50 - Information Disclosure
Title source: ruleDescription
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
Exploits (3)
exploitdb
WORKING POC
by Vahagn Vardanyan · pythonwebappsmultiple
https://www.exploit-db.com/exploits/43495
References (8)
Scores
CVSS v3
5.3
EPSS
0.6229
EPSS Percentile
98.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation Intel
CISA KEV
2022-06-09
VulnCheck KEV
2022-06-09
InTheWild.io
2022-06-09
ENISA EUVD
EUVD-2016-3472
Classification
CWE
CWE-200
Status
draft
Affected Products (1)
sap/netweaver_application_server_java
< 7.50
Timeline
Published
Feb 16, 2016
KEV Added
Jun 09, 2022
Tracked Since
Feb 18, 2026