PT-2016-3362 · Sap · Sap Netweaver As Java

Published

2016-03-09

·

Updated

2025-04-03

·

CVE-2016-9563

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS JAVA version 7.5
Description The issue is related to an XML External Entity (XXE) vulnerability in the BC-BMT-BPM-DSK component of SAP NetWeaver AS JAVA. This vulnerability allows remote authenticated users to conduct XXE attacks via the "sap.comtcbpemhimuwlconnproviderweb/bpemuwlconn" URI. The vulnerability is associated with insufficient restrictions on XML external entities, which can be exploited by a remote attacker to conduct XXE attacks.
Recommendations For SAP NetWeaver AS JAVA version 7.5, apply the fix provided in SAP Security Note 2296909 to resolve the issue. As a temporary workaround, consider restricting access to the BC-BMT-BPM-DSK component to minimize the risk of exploitation. Avoid using the vulnerable URI "sap.comtcbpemhimuwlconnproviderweb/bpemuwlconn" until the issue is resolved.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2021-05600
CVE-2016-9563

Affected Products

Sap Netweaver As Java