CVE-2016-2388
KEV PoC ×5largeUnauthenticated Information Disclosure in SAP NetWeaver AS Java 7.4
CISA: SAP NetWeaver Information Disclosure Vulnerability
CVE-2016-2388 is an unauthenticated information disclosure flaw (CWE-200) in the Universal Worklist (UWL) configuration component of SAP NetWeaver Application Server (AS) Java 7.4, addressed by SAP Security Note 2256846. A remote attacker triggers it by sending a specially crafted HTTP request to the UWL configuration interface without any credentials. Successful exploitation discloses sensitive user information stored by the system (low confidentiality impact only, with no integrity or availability impact per the CVSS vector). Any organization running SAP NetWeaver AS Java 7.4 — particularly where the UWL configuration interface is reachable from untrusted networks — is affected. Public proof-of-concept code has circulated since 2016, EPSS assigns a 51.6% 30-day exploitation probability (99th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-09, confirming exploitation in the wild; any ransomware association is unknown.
What to do: Apply the fix for SAP Security Note 2256846 or move NetWeaver AS Java to a patched release per SAP's vendor instructions, prioritizing internet-facing systems (patching is mandatory for US federal agencies under the KEV listing). Restrict network access to the UWL configuration interface, and review HTTP access logs for unexpected unauthenticated requests against UWL endpoints, since available PoCs are simple crafted HTTP requests.
| SAP NetWeaver Application Server (AS) Java | 7.4 (public PoC references also list NetWeaver AS Java 7.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver application server java
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.