← Browse

CVE-2016-2388

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
52.2%
98.9th percentile
CISA KEV
Listed
Added 2022-06-09 · patch by 2022-06-30
Weakness / dates
Published — · modified —

Description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

Official: NVD · CVE.org