CVE-2016-2386
CRITICAL(9.8)KEVLikely Exploited
SAP NetWeaver SQL Injection Vulnerability
Description
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver application server java | 7.40 |
Multiple CVSS Assessments
Source: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-Injection.html(Exploit, Third Party Advisory, VDB Entry)
- http://seclists.org/fulldisclosure/2016/May/56(Exploit, Mailing List, Third Party Advisory)
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulnerability/(Broken Link, Third Party Advisory)
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/(Broken Link, Third Party Advisory)
- https://github.com/vah13/SAP_exploit(Exploit, Third Party Advisory)
- https://www.exploit-db.com/exploits/39840/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/43495/(Exploit, Third Party Advisory, VDB Entry)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.