Vulnerability Description
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.40 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-InjectExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/May/56ExploitMailing ListThird Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulBroken LinkThird Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/Broken LinkThird Party Advisory
- https://github.com/vah13/SAP_exploitExploitThird Party Advisory
- https://www.exploit-db.com/exploits/39840/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43495/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/137129/SAP-NetWeaver-AS-JAVA-7.5-SQL-InjectExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/May/56ExploitMailing ListThird Party Advisory
- https://erpscan.io/advisories/erpscan-16-011-sap-netweaver-7-4-sql-injection-vulBroken LinkThird Party Advisory
- https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/Broken LinkThird Party Advisory
- https://github.com/vah13/SAP_exploitExploitThird Party Advisory
- https://www.exploit-db.com/exploits/39840/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43495/ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-US Government Resource
FAQ
What is CVE-2016-2386?
CVE-2016-2386 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
How severe is CVE-2016-2386?
CVE-2016-2386 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2386?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Java.