← Vulnerability feed

Vulnerability record · CVE-2016-2388 · published 16 February 2016

CVE-2016-2388: SAP NetWeaver AS Java Universal Worklist information disclosure

Sap · Netweaver Application Server Java

The Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an information exposure issue (CWE-200) that leaks user data without requiring credentials, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

5.3 CVSS 3.1 Medium CISA KEV since 9 Jun 2022 EPSS 52% · top 1.1% CWE-200 · Information exposure
5.3CVSS 3.1 base score, v2 5.0
52%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is unauthenticated and remotely reachable, has public exploit code, and is listed in CISA KEV, though the CVSS impact is limited to confidentiality.

What it is

The Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an information exposure issue (CWE-200) that leaks user data without requiring credentials, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An unauthenticated remote attacker can read sensitive user information from the affected SAP Java stack, which can support reconnaissance and follow-on attacks against the platform.

Attack surface

Reachable over the network via HTTP against the Universal Worklist Configuration component; the CVSS vector shows no privileges and no user interaction required.

Exploitation

CVE-2016-2388 is in CISA KEV (added 2022-06-09) and has a high EPSS 30-day probability of about 0.52 (98.9th percentile), with public exploit references on Exploit-DB, Packet Storm and Full Disclosure.

What to do

  • Apply the fix per SAP Security Note 2256846 and the vendor instructions referenced in CISA KEV.
  • Restrict network access to the SAP NetWeaver AS Java Universal Worklist endpoints to trusted networks or reverse proxies.
  • Review and harden Universal Worklist configuration to avoid exposing user data to unauthenticated requests.
  • Monitor SAP security notes and apply current NetWeaver AS Java patch levels beyond the 7.4 baseline.
  • If patching is delayed, isolate the affected Java stack from untrusted networks and increase logging on its HTTP interfaces.

Detection

  • Inspect HTTP access logs for crafted requests to Universal Worklist Configuration endpoints returning user data to unauthenticated clients.
  • Alert on anomalous or repeated requests to SAP NetWeaver AS Java worklist paths from external or unexpected source IPs.
  • Correlate web server and SAP Java logs for information-disclosure patterns against the Universal Worklist component.
  • Track exploitation attempts using the public PoC references and known request signatures where available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-2388 to the Known Exploited Vulnerabilities catalog on 9 June 2022 as "SAP NetWeaver Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 30 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/137128/SAP-NetWeaver-AS-JAVA-7.5-Information-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/145860/SAP-NetWeaver-J2EE-Engine-7.40-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/May/55 ExploitMailing ListThird Party Advisory
https://erpscan.io/advisories/erpscan-16-010-sap-netweaver-7-4-information-disclosure/ Broken LinkThird Party Advisory
https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/ Broken LinkThird Party Advisory
https://www.exploit-db.com/exploits/39841/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/43495/ ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/137128/SAP-NetWeaver-AS-JAVA-7.5-Information-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/145860/SAP-NetWeaver-J2EE-Engine-7.40-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/May/55 ExploitMailing ListThird Party Advisory
https://erpscan.io/advisories/erpscan-16-010-sap-netweaver-7-4-information-disclosure/ Broken LinkThird Party Advisory
https://erpscan.io/press-center/blog/sap-security-notes-february-2016-review/ Broken LinkThird Party Advisory
https://www.exploit-db.com/exploits/39841/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/43495/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2388 US Government Resource

Track CVE-2016-2388 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed10.0CVE-2010-5326SAP NetWeaver Java Invoker Servlet unauthenticated remote code executionThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attacke…KEVEPSS 18%analysed9.8CVE-2016-2386SAP NetWeaver UDDI Server SQL InjectionThe UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command executio…KEVEPSS 72%analysed7.5CVE-2017-12637SAP NetWeaver Java directory traversal allows arbitrary file readSAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attack…KEVEPSS 95%analysed7.5CVE-2016-3976SAP NetWeaver AS Java directory traversal in CrashFileDownloadServletSAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A re…KEVEPSS 47%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2016-2388), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.