First published: Wed Nov 23 2016(Updated: )
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Java Application Server | =7.50 | |
SAP NetWeaver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9563 has a medium severity level due to its potential to allow XML External Entity (XXE) attacks.
To mitigate CVE-2016-9563, apply the relevant patches provided in SAP Security Note 2296909.
CVE-2016-9563 impacts users of SAP NetWeaver AS JAVA version 7.50.
CVE-2016-9563 allows for remote authenticated users to conduct XML External Entity (XXE) attacks.
Yes, remote authenticated access is required to exploit CVE-2016-9563.