""ET WEB_SPECIFIC_APPS Vulnerable SAP NetWeaver Path Observed - Information Disclosure (CVE-2016-2388)""

SID: 2038697

Revision: 2

Class Type: attempted-recon

Metadata: attack_target Web_Server, created_at 2022_08_31, cve CVE_2016_2388, deployment Perimeter, deployment SSLDecrypt, signature_severity Informational, updated_at 2023_04_28

Reference:

  • cve

  • 2016-2388

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: [$HOME_NET,$HTTP_SERVERS]

Destination Port: any

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: "/webdynpro/resources/"

  • Value: "/JWFTestAddAssignees#"

Within:

PCRE:

Special Options:

  • http_method

  • http_uri

  • http_uri

  • fast_pattern

source