← Vulnerability feed

Vulnerability record · CVE-2016-2386 · published 16 February 2016

CVE-2016-2386: SAP NetWeaver UDDI Server SQL Injection

Sap · Netweaver Application Server Java

The UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command execution. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, making it a high-value target for initial access.

9.8 CVSS 3.1 Critical CISA KEV since 9 Jun 2022 EPSS 72% · top 0.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
72%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection with a 9.8 CVSS score, CISA KEV listing, and very high EPSS probability makes this an urgent patch target.

What it is

The UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command execution. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, making it a high-value target for initial access.

Impact

An unauthenticated remote attacker can execute arbitrary SQL commands against the underlying database, potentially reading, modifying, or deleting data and, depending on database privileges, escalating to broader system compromise.

Attack surface

Reachable over the network via the UDDI server component of the J2EE Engine; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is required.

Exploitation

CVE-2016-2386 is listed in CISA KEV (added 2022-06-09) and has a 30-day EPSS probability of 0.7106 (99.37th percentile); multiple public exploit references are tagged, indicating active exploitation and widely available proof-of-concept code.

What to do

  • Apply the fix per SAP Security Note 2101079 and the vendor update referenced in CISA KEV.
  • Restrict network access to the UDDI server and J2EE Engine management interfaces to trusted hosts only.
  • Run the affected database and application with least-privilege accounts to limit SQL injection impact.
  • Monitor SAP security notes and apply subsequent NetWeaver J2EE patches promptly.
  • If patching is delayed, consider disabling or isolating the UDDI service if it is not required.

Detection

  • Inspect UDDI server and J2EE Engine HTTP logs for SQL metacharacters, UNION, or stacked query patterns in request parameters.
  • Alert on anomalous database queries or errors originating from the SAP application server.
  • Monitor for outbound connections or process behavior consistent with post-exploitation following SQL injection.
  • Use the public exploit references to build signatures for known UDDI SQL injection payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-2386 to the Known Exploited Vulnerabilities catalog on 9 June 2022 as "SAP NetWeaver SQL Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 30 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2386 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed10.0CVE-2010-5326SAP NetWeaver Java Invoker Servlet unauthenticated remote code executionThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attacke…KEVEPSS 18%analysed7.5CVE-2017-12637SAP NetWeaver Java directory traversal allows arbitrary file readSAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attack…KEVEPSS 95%analysed7.5CVE-2016-3976SAP NetWeaver AS Java directory traversal in CrashFileDownloadServletSAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A re…KEVEPSS 47%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed5.3CVE-2016-2388SAP NetWeaver AS Java Universal Worklist information disclosureThe Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an inform…KEVEPSS 52%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2016-2386), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.