CVE-2016-2386

sap netweaver application server java

Published 16 Feb 2016 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 9 Jun 2022, with a remediation deadline of 30 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

References