CVE-2016-2388

CVE Published 2016-02-16
Related CWE(s) CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Related Vendor(s) sap
Related Product(s) netweaver_application_server_java
Exploitation Reported (CISA KEV) 2022-06-09
CVSS 3 Base Score 5.3 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References