CVE-2017-16349: XEE
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue authenticated HTTP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16349?
CVE-2017-16349 is considered a high-severity vulnerability due to the potential for information disclosure and denial of service.
How do I fix CVE-2017-16349?
To fix CVE-2017-16349, update SAP Business Planning and Consolidation to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2017-16349?
CVE-2017-16349 is an XML External Entity (XXE) vulnerability related to the processing of specially crafted XML requests.
What can an attacker achieve with CVE-2017-16349?
An attacker exploiting CVE-2017-16349 can potentially access sensitive information and may cause denial of service.
Which software is affected by CVE-2017-16349?
CVE-2017-16349 affects SAP Business Planning and Consolidation, specifically its reporting functionality.