PoC Index

CVE-2016-2386

KEVCRITICAL 9.8EPSS 71.1%

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
71.06% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2022-06-09
Published
2016-02-16
Updated
2025-10-21

Proof-of-concept exploits (4)

ExploitDB entries (2)

References

Related