Umbra Wiki cve cve/CVE-2016-2386
Back to wiki

CVE-2016-2386 — SAP NetWeaver SQL Injection Vulnerability

provenance: imported · CVE: CVE-2016-2386

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SAP
Product NetWeaver
Date added 2022-06-09
Due date 2022-06-30
Ransomware campaign use Unknown

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2016-2386

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2016-2386
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog