LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-2388: SAP NetWeaver Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 9, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 30, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-2388 to its Known Exploited Vulnerabilities catalog on Jun 9, 2022, with a federal patch deadline of Jun 30, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

CVE-2016-2388 is an information disclosure vulnerability in the Universal Worklist Configuration component of SAP NetWeaver AS JAVA. It allows a remote attacker to obtain sensitive user information by sending a crafted HTTP request. For organizations running SAP NetWeaver, this matters because exposed user details can aid further targeting, credential abuse, or lateral movement inside enterprise environments that often hold critical business data.

Public detail is limited to the component and weakness class described in the advisory; teams should treat any SAP NetWeaver AS JAVA deployment that includes the Universal Worklist as potentially in scope until confirmed otherwise against the vendor advisory.

How it works

The flaw is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). In this case, the Universal Worklist Configuration in SAP NetWeaver AS JAVA does not adequately restrict access to certain user-related data. An unauthenticated or low-privilege remote attacker can craft an HTTP request that elicits a response containing sensitive user information that should not be returned.

Exact request structure, parameters, and response contents are not detailed in the provided facts. Defenders should assume a straightforward HTTP-based information leak rather than a complex memory-corruption or injection chain, and must verify the precise attack surface and any authentication requirements directly from the vendor advisory. Successful abuse yields user information that can be leveraged for reconnaissance or follow-on attacks; ransomware use of this CVE is not documented.

Am I affected? How to find it in your systems

SAP NetWeaver AS JAVA commonly underpins enterprise portals, business process orchestration, and integration scenarios. The Universal Worklist is typically present in environments that surface task lists or workflow items to end users.

Because exact affected patch levels beyond the stated AS JAVA 7.4 reference are not supplied here, cross-check every discovered instance against the official vendor advisory before declaring a system clean.

How to remediate

The required action is to apply updates per vendor instructions. Obtain the security notes or support packages that address CVE-2016-2388 from SAP, test them in a non-production environment that mirrors your Universal Worklist configuration, then deploy to production following your normal change process.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches even when ransomware use is not documented. If logs or other evidence suggest the vulnerability was abused, treat any returned user information as compromised, reset affected credentials, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in prior compromises and to prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
WeaknessCWE-200
Added to CISA KEVJun 9, 2022
Federal patch deadlineJun 30, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities