CVE-2016-9563
published 2016-11-23CVE-2016-9563: BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the…
PriorityP277medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
23.80%
97.6th percentile
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for XXE attack patterns (e.g., DOCTYPE declarations, external entity references) in HTTP requests targeting the BC-BMT-BPM-DSK component URI on SAP NetWeaver AS JAVA 7.5 ↗
- →Restrict and alert on authenticated remote access to the BC-BMT-BPM-DSK component endpoint, as exploitation requires only remote authentication ↗
- ·Exploitation requires remote authenticated access only — no additional privileges needed, lowering the bar for abuse by any valid SAP account ↗
- ·Affected platform is specifically SAP NetWeaver AS JAVA 7.5; confirm version before scoping detection or patching efforts ↗
- ·CISA KEV listing confirms active exploitation in the wild; vendor patch (SAP Security Note 2296909) should be treated as urgent ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqg2-q88q-5h4p: BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7
ghsa_unreviewed·2022-04-30
CVE-2016-9563 [MEDIUM] CWE-611 GHSA-pqg2-q88q-5h4p: BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
VulnCheck
SAP NetWeaver XML External Entity (XXE) Vulnerability
vulncheck·2016·CVSS 6.5
CVE-2016-9563 [MEDIUM] CWE-611 SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
Affected: SAP NetWeaver
Required Action: Apply updates per vendor instructions.
Exploitation References: https://digital.nhs.uk/cyber-alerts/2021/cc-3815; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.csoonline.com/article/3674119/most-common-sap-vulnerabilities-attackers-try-to-exploit.html
Remediation Due: 2022-05-03
CISA
SAP NetWeaver XML External Entity (XXE) Vulnerability
cisa·2021-11-03·CVSS 6.5
CVE-2016-9563 [MEDIUM] CWE-611 SAP NetWeaver XML External Entity (XXE) Vulnerability
Vulnerability: SAP NetWeaver XML External Entity (XXE) Vulnerability
Affected: SAP NetWeaver
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-9563
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/92419https://erpscan.io/advisories/erpscan-16-034-sap-netweaver-java-xxe-vulnerability-bc-bmt-bpm-dsk-component/https://launchpad.support.sap.com/#/notes/2296909http://www.securityfocus.com/bid/92419https://erpscan.io/advisories/erpscan-16-034-sap-netweaver-java-xxe-vulnerability-bc-bmt-bpm-dsk-component/https://launchpad.support.sap.com/#/notes/2296909https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9563
2016-11-23
Published
2021-11-03
Added to CISA KEV
Exploited in the wild