CVE-2016-2386CISA KEVEPSS p99.3%

CVE-2016-2386SAP NetWeaver SQL Injection Vulnerability

SAP / NetWeaver

Description

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Scoring

EPSS71.06% probability of exploitation · percentile 99.3% · 2026-06-19T12:03:05Z

CISA KEV entry

Added to KEV: 2022-06-09

(incoming)1

TypeTargetConfidenceTier
KEVEntrySAP NetWeaver SQL Injection Vulnerabilitykev-cve-2016-23860%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
SAP NetWeaver Information Disclosure Vulnerability
CVE
CVE-2026-27674
CVE
CVE-2026-34260
CVE
CVE-2026-44746
CVE
CVE-2026-40135
CVE
CVE-2026-44744
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.