EXPOSURES › CVE-2016-2388
CVE-2016-2388
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old.
A vulnerability in SAP NetWeaver AS JAVA 7.4 allowed attackers to extract sensitive user data through crafted HTTP requests, demonstrating a failure to properly sanitize input. DIB organizations using this product face potential data breaches and compliance violations (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3) and should immediately patch or mitigate the vulnerability.
Shame score — The vulnerability's continued exploitation highlights a failure to maintain adequate patching and security controls for a widely-used enterprise software product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |