ZeroHour

CVE-2016-2388

KEV PoC ×5large

Unauthenticated Information Disclosure in SAP NetWeaver AS Java 7.4

CISA: SAP NetWeaver Information Disclosure Vulnerability

CVSS 3.1
5.3 medium
EPSS
52%p99
Published
()
KEV added
AI analysis

CVE-2016-2388 is an unauthenticated information disclosure flaw (CWE-200) in the Universal Worklist (UWL) configuration component of SAP NetWeaver Application Server (AS) Java 7.4, addressed by SAP Security Note 2256846. A remote attacker triggers it by sending a specially crafted HTTP request to the UWL configuration interface without any credentials. Successful exploitation discloses sensitive user information stored by the system (low confidentiality impact only, with no integrity or availability impact per the CVSS vector). Any organization running SAP NetWeaver AS Java 7.4 — particularly where the UWL configuration interface is reachable from untrusted networks — is affected. Public proof-of-concept code has circulated since 2016, EPSS assigns a 51.6% 30-day exploitation probability (99th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-09, confirming exploitation in the wild; any ransomware association is unknown.

What to do: Apply the fix for SAP Security Note 2256846 or move NetWeaver AS Java to a patched release per SAP's vendor instructions, prioritizing internet-facing systems (patching is mandatory for US federal agencies under the KEV listing). Restrict network access to the UWL configuration interface, and review HTTP access logs for unexpected unauthenticated requests against UWL endpoints, since available PoCs are simple crafted HTTP requests.

Affected
SAP NetWeaver Application Server (AS) Java7.4 (public PoC references also list NetWeaver AS Java 7.5)
Estimated exposure
large≈ tens of thousands of internet-exposed SAP NetWeaver AS Java instances (subset on 7.4 with UWL reachable unknown) — SAP NetWeaver AS Java is widely deployed in enterprise estates and public internet scans have repeatedly identified on the order of tens of thousands of exposed NetWeaver AS Java instances, though the share running 7.4 with the UWL…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sap
Products
netweaver application server java
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.