First published: Tue Feb 16 2016(Updated: )
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
SAP NetWeaver AS JAVA | =7.40 | |
=7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2386 is considered a critical SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
To fix CVE-2016-2386, you should apply the patches provided in SAP Security Note 2101079 immediately.
CVE-2016-2386 affects SAP NetWeaver J2EE Engine version 7.40.
If exploited, CVE-2016-2386 allows attackers to gain unauthorized access to the database and execute arbitrary queries.
Currently, the recommended approach is to apply the security patches, as there are no effective workarounds for CVE-2016-2386.