CVE-2016-2386
KEV PoC ×5largeUnauthenticated SQL Injection in SAP NetWeaver AS Java UDDI Server
CISA: SAP NetWeaver SQL Injection Vulnerability
CVE-2016-2386 is a SQL injection flaw (CWE-89) in the UDDI server component of SAP NetWeaver AS Java (J2EE Engine), fixed under SAP Security Note 2101079. The CVE description cites version 7.40, and public proof-of-concept exploits also demonstrate the issue on AS Java 7.5; it is triggered remotely via unspecified inputs to the UDDI service, requiring no authentication and no user interaction. A successful attacker can execute arbitrary SQL commands against the underlying database, with high impact on data confidentiality and integrity. Any organization running an affected SAP NetWeaver AS Java system where the UDDI service is reachable — especially internet-facing instances — is exposed. Exploitation is well established: multiple public PoCs exist, EPSS assigns a 71.1% probability of exploitation within 30 days, and the flaw was added to CISA's KEV catalog on 2022-06-09, indicating known in-the-wild use.
What to do: Apply the fix referenced in SAP Security Note 2101079 per vendor instructions on all affected NetWeaver AS Java 7.40/7.5 instances, prioritizing internet-exposed systems, and verify patch status against the KEV required action. As an interim mitigation, restrict network access to the UDDI service. Review HTTP/UDDI access logs on unpatched systems for signs of exploitation.
| SAP NetWeaver Application Server Java (AS Java) - UDDI server | 7.40 (per CVE description); 7.5 also shown vulnerable in public PoCs |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver application server java
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.