Umbra Wiki cve cve/CVE-2016-2386
Back to wiki

CVE-2016-2386 — SAP NetWeaver SQL Injection Vulnerability

provenance: imported · CVE: CVE-2016-2386 · CWE: CWE-89

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SAP
Product NetWeaver
Date added 2022-06-09
Due date 2022-06-30
Ransomware campaign use Unknown

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2016-2386

Weakness behind it

CISA records this vulnerability as an instance of CWE-89. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2016-2386
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →