CISA Known Exploited Vulnerability

CVE-2016-2388

SAP · NetWeaver

SAP NetWeaver Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-200
Ransomware Unknown

CISA description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

Required action

Apply updates per vendor instructions.