Loading
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
Use CWE-200, Sap vendor hub and Netweaver Application Server Java product page to widen CVE-2016-2388 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-40309, CVE-2024-22127 and CVE-2024-24743 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.