CISA Known Exploited Vulnerability

CVE-2016-9563

SAP · NetWeaver

SAP NetWeaver XML External Entity (XXE) Vulnerability

Date added
BOD 22-01 due date
CWE CWE-611
Ransomware Unknown

CISA description

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

Required action

Apply updates per vendor instructions.