CVE-2016-2388 is an information disclosure vulnerability affecting the Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4. This flaw allows remote, unauthenticated attackers to obtain sensitive user information through specially crafted HTTP requests. With a CVSS score of 5.3 (Medium), it is easily exploitable over the network with low attack complexity and no user interaction required, leading to a potential compromise of confidentiality. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community discussion and media coverage, including an article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.10, <= 7.50CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.