Junglewise Threat Intelligence

CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability

CVE-2016-9563 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2021-11-03

Technologies: SAP NetWeaver AS Java (SERVERCORE), SAP NetWeaver. Vendors: SAP.

Executive brief

The BC-BMT-BPM-DSK component in SAP NetWeaver AS JAVA 7.5 is vulnerable to XML External Entity (XXE) attacks. Remote authenticated users can exploit this via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI to conduct unauthorized data retrieval.

Affected products

  • SAP NetWeaver AS JAVA 7.5

Timeline

  • 2016-08-10: disclosed: Initial security focus and third-party advisory disclosure
  • 2016-11-23: advisory: NIST NVD initial analysis published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats