CVE-2016-2388CISA KEVEPSS p98.8%

CVE-2016-2388SAP NetWeaver Information Disclosure Vulnerability

SAP / NetWeaver

Description

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

Scoring

EPSS51.55% probability of exploitation · percentile 98.8% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-06-09

(incoming)1

TypeTargetConfidenceTier
KEVEntrySAP NetWeaver Information Disclosure Vulnerabilitykev-cve-2016-23880%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
SAP NetWeaver SQL Injection Vulnerability
CVE
CVE-2025-0066
CVE
SAP Multiple Products HTTP Request Smuggling Vulnerability
CVE
CVE-2026-27674
CVE
CVE-2026-40128
CVE
CVE-2025-42922
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.