CVE-2016-9563

MEDIUM KEV

SAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection via BPEM UWL Connection Provider

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-9563 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.

Description

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92419
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2296909

Scores

CVSS v3 6.5
EPSS 0.5878
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-08
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2016-10369
CWE
CWE-611
Status published
Products (1)
sap/netweaver_application_server_java 7.50
Published Nov 23, 2016
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026