CVE-2016-3974
published 2016-04-07CVE-2016-3974: XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of…
PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EXPLOIT
EPSS
15.06%
96.3th percentile
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | 7.10 – 7.50 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted XML requests targeting the SAP NetWeaver Java AS Configuration Wizard endpoint at _tc~monitoring~webservice~web/ServerNodesWSService, which may indicate XXE exploitation attempts (DoS, SMB Relay, or file read). ↗
- →Watch for outbound SMB connections originating from the SAP NetWeaver Java AS server following receipt of XML requests to the vulnerable endpoint, which may indicate an SMB Relay attack triggered via XXE. ↗
- →External entity references pointing to attacker-controlled hosts (e.g., attacker.com) in XML payloads sent to the SAP endpoint may indicate active XXE exploitation. ↗
- ·The vulnerability affects SAP NetWeaver Java AS versions 7.1 through 7.5 only; patched systems (SAP Security Note 2235994) are not affected. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/137527/SAP-NetWeaver-AS-JAVA-7.5-XXE-Injection.htmlhttp://seclists.org/fulldisclosure/2016/Jun/41https://erpscan.io/advisories/erpscan-16-013-sap-netweaver-7-4-ctcprotocol-servlet-xxe/https://erpscan.io/press-center/blog/sap-security-notes-march-2016-review/https://www.exploit-db.com/exploits/39995/http://packetstormsecurity.com/files/137527/SAP-NetWeaver-AS-JAVA-7.5-XXE-Injection.htmlhttp://seclists.org/fulldisclosure/2016/Jun/41https://erpscan.io/advisories/erpscan-16-013-sap-netweaver-7-4-ctcprotocol-servlet-xxe/https://erpscan.io/press-center/blog/sap-security-notes-march-2016-review/https://www.exploit-db.com/exploits/39995/
2016-04-07
Published