← לוח פגיעויות

CVE-2016-2388

בינונית 5.3 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
SAP NetWeaver Information Disclosure Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
52% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-200

מוצרים מושפעים

sap: netweaver application server java

קישורים