CISA Known Exploited Vulnerability

CVE-2016-2386

SAP · NetWeaver

SAP NetWeaver SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Unknown

CISA description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Required action

Apply updates per vendor instructions.