Junglewise Threat Intelligence

CVE-2016-2388: SAP NetWeaver Information Disclosure Vulnerability

CVE-2016-2388 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2022-06-09

Technologies: SAP NetWeaver AS Java (SERVERCORE), SAP NetWeaver. Vendors: SAP.

Executive brief

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. This vulnerability is also tracked under SAP Security Note 2256846.

Affected products

  • SAP NetWeaver AS JAVA 7.4

Timeline

  • 2016-02-01: disclosed: SAP Security Note 2256846 released.
  • 2022-06-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats