LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 9, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 30, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-2386 to its Known Exploited Vulnerabilities catalog on Jun 9, 2022, with a federal patch deadline of Jun 30, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2016-2386 is a SQL injection vulnerability in the UDDI server component of SAP NetWeaver J2EE Engine 7.40. It allows a remote attacker to send crafted input that the application incorporates into database queries without proper validation, potentially letting them run arbitrary SQL commands. For organizations running SAP NetWeaver, this matters because the UDDI server is part of the enterprise application stack that often sits near business data; successful abuse can lead to unauthorized data access, modification, or further compromise of the application tier. Confirm exact affected builds and fixed releases against the vendor advisory.

How it works

This issue is classified as CWE-89 (SQL injection). In products of this class, user- or network-supplied data reaches a database query string without adequate sanitization or parameterization. An attacker who can reach the UDDI server over the network supplies input through unspecified vectors that the server then embeds into SQL statements. If the injection succeeds, the attacker can alter the intended query logic—reading, changing, or deleting data the application account is allowed to touch, or in some environments chaining to further actions. Public detail on the precise request format or parameters is limited; treat any reachable UDDI endpoint on an unpatched NetWeaver J2EE Engine 7.40 instance as potentially exploitable until verified otherwise against the vendor advisory.

Am I affected? How to find it in your systems

SAP NetWeaver commonly runs as the application platform for SAP business suites, portals, and integration services, often on dedicated application servers or in larger SAP landscapes. Inventory steps:

How to remediate

Patch first. Apply the updates provided by SAP for this vulnerability exactly as described in the vendor advisory and related security notes. CISA’s required action is to apply updates per vendor instructions. After patching:

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access to application and business data. Known ransomware use of this CVE is not documented, but that does not rule out other forms of compromise. If you suspect exposure, follow your incident response process: isolate affected systems as appropriate, preserve logs, review database and application audit trails for unauthorized queries or data access, and rotate credentials that may have been at risk. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then prioritize password resets and monitoring for any confirmed hits.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
WeaknessCWE-89
Added to CISA KEVJun 9, 2022
Federal patch deadlineJun 30, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities