Executive brief
The BC-BMT-BPM-DSK component in SAP NetWeaver AS JAVA 7.5 is vulnerable to XML External Entity (XXE) attacks. Remote authenticated users can exploit this via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI to conduct unauthorized data retrieval.
Affected products
- SAP NetWeaver AS JAVA 7.5
Timeline
- 2016-08-10: disclosed: Initial security focus and third-party advisory disclosure
- 2016-11-23: advisory: NIST NVD initial analysis published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog