← Back to browse · API

CVE-2016-2388

Severity
MEDIUM
CVSS
5.3
EPSS
0.51553
Risk score
64.24
CISA KEV
Yes
PoC
No
Published
2016-02-16
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2016-3472, GHSA-56QQ-X77R-G35X
Products
SAP:NetWeaver, n/a:n/a n/a
Sources
cisa.gov CVE-2016-2388
euvd EUVD-2016-3472

Description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

References