Vulnerability record · CVE-2016-2388 · published 16 February 2016
CVE-2016-2388: SAP NetWeaver AS Java Universal Worklist information disclosure
Sap · Netweaver Application Server Java
The Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an information exposure issue (CWE-200) that leaks user data without requiring credentials, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is unauthenticated and remotely reachable, has public exploit code, and is listed in CISA KEV, though the CVSS impact is limited to confidentiality.
What it is
The Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an information exposure issue (CWE-200) that leaks user data without requiring credentials, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated remote attacker can read sensitive user information from the affected SAP Java stack, which can support reconnaissance and follow-on attacks against the platform.
Attack surface
Reachable over the network via HTTP against the Universal Worklist Configuration component; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CVE-2016-2388 is in CISA KEV (added 2022-06-09) and has a high EPSS 30-day probability of about 0.52 (98.9th percentile), with public exploit references on Exploit-DB, Packet Storm and Full Disclosure.
What to do
- Apply the fix per SAP Security Note 2256846 and the vendor instructions referenced in CISA KEV.
- Restrict network access to the SAP NetWeaver AS Java Universal Worklist endpoints to trusted networks or reverse proxies.
- Review and harden Universal Worklist configuration to avoid exposing user data to unauthenticated requests.
- Monitor SAP security notes and apply current NetWeaver AS Java patch levels beyond the 7.4 baseline.
- If patching is delayed, isolate the affected Java stack from untrusted networks and increase logging on its HTTP interfaces.
Detection
- Inspect HTTP access logs for crafted requests to Universal Worklist Configuration endpoints returning user data to unauthenticated clients.
- Alert on anomalous or repeated requests to SAP NetWeaver AS Java worklist paths from external or unexpected source IPs.
- Correlate web server and SAP Java logs for information-disclosure patterns against the Universal Worklist component.
- Track exploitation attempts using the public PoC references and known request signatures where available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-2388 to the Known Exploited Vulnerabilities catalog on 9 June 2022 as "SAP NetWeaver Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 30 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2388 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2388), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.