V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2016-2386
CVE
Critical KEVConfirmedExploit available

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands …

CVSS
9.8
Critical
EPSS
0.71
p99
Published
2016-01-01
Updated
2022-06-09
Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Tags · CWE
KEVPre-authSQLi
CWE-89
CAPEC-7
CAPEC-66
CAPEC-108
CAPEC-109
CAPEC-110
CAPEC-470
Affected products
Netweaver_application_server_java
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2016-01-01
Published
2022-06-09
Added to KEV
2022-06-09
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.711 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
39840
exploitdb · https://www.exploit-db.com/exploits/39840
Enterprise
43495
exploitdb · https://www.exploit-db.com/exploits/43495
Enterprise
CVE-2016-2386
github-poc · https://github.com/murataydemir/CVE-2016-2386
Enterprise
Affected products
ProductVendorStatus
netweaver_application_server_java*Exploited
Source databases
CVE
Related vulnerabilities