Back
CVE-2016-2386
CRITICAL
CISA KEV
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
Published: Feb 16, 2016
Modified: Apr 21, 2026
CWE-89
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_application_server_java | 7.40 |
GitHub Security Advisory GHSA-g384-79gw-fwh4
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote...
References (15)
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/May/56 Exploit, Mailing List, Third Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/ Broken Link, Third Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/ Broken Link, Third Party Advisory
- https://github.com/vah13/SAP_exploit Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/39840/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43495/ Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/May/56 Exploit, Mailing List, Third Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/ Broken Link, Third Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/ Broken Link, Third Party Advisory
- https://github.com/vah13/SAP_exploit Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/39840/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43495/ Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
44.46%
Top 2% most likely to be exploited
Threat Score
82.5 / 100
CISA Known Exploited
Date Added:
2022-06-09
Due Date:
2022-06-30
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub