Skip to content
COOEY

EXPOSURES › CVE-2016-9563

CVE-2016-9563

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-9563 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

SAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code.

SAP NetWeaver Application Server Java Platforms contained an XXE flaw in BC-BMT-BPM-DSK that let authenticated users read local files and run arbitrary code. DIBs must patch SAP NetWeaver immediately and disable XXE features to prevent data exfiltration and system compromise. This is a known, unpatched vulnerability that was actively exploited in the wild.

Shame score — SAP shipped a critical XXE flaw for years without a patch, allowing attackers to read files and execute code on systems that relied on SAP NetWeaver.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
SAP faced severe fallout for CVE-2016-9563, a critical XXE vulnerability in NetWeaver allowing remote authenticated attackers to exploit the flaw. The NVD entry confirms the severity, while other sour
cooey ↗ severe-fallout -0.80
NVD confirms critical XXE vulnerability in SAP NetWeaver, allowing remote authenticated attackers to exploit the flaw. No praise for SAP's handling is present in the provided text.
"SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks."
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Cisco vulnerabilities.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Cisco vulnerabilities.
www.dell.com ↗ severe-fallout +0.00
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Dell vulnerabilities.
securityonline.info ↗ severe-fallout +0.00
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Zimbra vulnerabilities.
NVD ↗ severe-fallout +0.00
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 vulnerabilities.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized