Vulnerability Details CVE-2016-9563
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.43
EPSS Ranking 97.4%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Proposed Action
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
Ransomware Campaign
Unknown
Products affected by CVE-2016-9563
-
cpe:2.3:a:sap:netweaver_application_server_java:7.50