CVE-2016-2388
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
- Affected products
- Sap Netweaver As Java
- Sap Netweaver Application Server Java
- ≤ 7.50
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 51.6% (99th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2016-02-16
CVE-2016-2388 at NVD
9 known exploits for CVE-2016-2388
Proof-of-concept code and exploit modules indexed by Sploitus
SAP NetWeaver J2EE Engine 7.40 SQL Injection
SAP NetWeaver J2EE Engine 7.40 - SQL Injection Exploit
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Sap Netweaver
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
SAP NetWeaver AS JAVA 7.1 7.5 - Information Disclosure
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
SAP NetWeaver AS JAVA 7.5 Information Disclosure