Junglewise Threat Intelligence

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

CVE-2016-2386 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-09

Technologies: SAP NetWeaver. Vendors: SAP.

Executive brief

A SQL injection vulnerability in the UDDI server of SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. The vulnerability is also identified by SAP Security Note 2101079.

Affected products

  • SAP NetWeaver J2EE Engine (UDDI server) 7.40

Timeline

  • 2016-02-10: advisory: SAP Security Note 2101079 released
  • 2022-06-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats