CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
Other sources
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9563?
CVE-2016-9563 has a medium severity level due to its potential to allow XML External Entity (XXE) attacks.
How do I fix CVE-2016-9563?
To mitigate CVE-2016-9563, apply the relevant patches provided in SAP Security Note 2296909.
Who is affected by CVE-2016-9563?
CVE-2016-9563 impacts users of SAP NetWeaver AS JAVA version 7.50.
What type of attacks can be executed using CVE-2016-9563?
CVE-2016-9563 allows for remote authenticated users to conduct XML External Entity (XXE) attacks.
Is remote access required to exploit CVE-2016-9563?
Yes, remote authenticated access is required to exploit CVE-2016-9563.