ZeroHour

CVE-2016-2386

KEV PoC ×5large

Unauthenticated SQL Injection in SAP NetWeaver AS Java UDDI Server

CISA: SAP NetWeaver SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
71%p99
Published
()
KEV added
AI analysis

CVE-2016-2386 is a SQL injection flaw (CWE-89) in the UDDI server component of SAP NetWeaver AS Java (J2EE Engine), fixed under SAP Security Note 2101079. The CVE description cites version 7.40, and public proof-of-concept exploits also demonstrate the issue on AS Java 7.5; it is triggered remotely via unspecified inputs to the UDDI service, requiring no authentication and no user interaction. A successful attacker can execute arbitrary SQL commands against the underlying database, with high impact on data confidentiality and integrity. Any organization running an affected SAP NetWeaver AS Java system where the UDDI service is reachable — especially internet-facing instances — is exposed. Exploitation is well established: multiple public PoCs exist, EPSS assigns a 71.1% probability of exploitation within 30 days, and the flaw was added to CISA's KEV catalog on 2022-06-09, indicating known in-the-wild use.

What to do: Apply the fix referenced in SAP Security Note 2101079 per vendor instructions on all affected NetWeaver AS Java 7.40/7.5 instances, prioritizing internet-exposed systems, and verify patch status against the KEV required action. As an interim mitigation, restrict network access to the UDDI service. Review HTTP/UDDI access logs on unpatched systems for signs of exploitation.

Affected
SAP NetWeaver Application Server Java (AS Java) - UDDI server7.40 (per CVE description); 7.5 also shown vulnerable in public PoCs
Estimated exposure
largeestimated tens of thousands of exposed systems (clearly an estimate) — SAP NetWeaver is the ERP backbone for a large share of large enterprises and thousands of AS Java instances are observable on the public internet in historical scan data, though only deployments with the UDDI service reachable are actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sap
Products
netweaver application server java
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.