CVE-2016-2386
sap netweaver application server java
Published 16 Feb 2016 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 9 Jun 2022, with a remediation deadline of 30 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
References
- packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html · Exploit, Third Party Advisory, VDB Entry
- seclists.org/fulldisclosure/2016/May/56 · Exploit, Mailing List, Third Party Advisory
- erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/ · Broken Link, Third Party Advisory
- erpscan.io/press-center/blog/sap-security-notes-february-2016-review/ · Broken Link, Third Party Advisory
- github.com/vah13/SAP_exploit · Exploit, Third Party Advisory
- www.exploit-db.com/exploits/39840/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/43495/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386 · US Government Resource