CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2016-2386

CVSS 9.8v3.1pub. 2016-02-16upd. 2026-04-21

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sap Netweaver Application Server Java

    APP
    Sap
    7.40

CISA KEV — detailsi

Vendori
SAP
Producti
NetWeaver
Added to KEVi
June 9, 2022
Remediation deadline (US Federal)i
June 30, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 czerwca 2022
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard

CVE-2010-5326CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia

CVE-2024-22127CRITICAL9.1PL ✓same product

SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2022-22532CRITICAL9.8PL ✓same product

SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP