EXPOSURES › CVE-2016-9563
CVE-2016-9563
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code.
SAP NetWeaver Application Server Java Platforms contained an XXE flaw in BC-BMT-BPM-DSK that let authenticated users read local files and run arbitrary code. DIBs must patch SAP NetWeaver immediately and disable XXE features to prevent data exfiltration and system compromise. This is a known, unpatched vulnerability that was actively exploited in the wild.
Shame score — SAP shipped a critical XXE flaw for years without a patch, allowing attackers to read files and execute code on systems that relied on SAP NetWeaver.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
"SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks."
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |