CVE-2016-9563
KEVlargeAuthenticated XXE in SAP NetWeaver Application Server Java (BPM component)
CISA: SAP NetWeaver XML External Entity (XXE) Vulnerability
CVE-2016-9563 is an XML External Entity (XXE) injection flaw (CWE-611) in SAP NetWeaver Application Server for Java, located in the BC-BMT-BPM-DSK (Business Process Management) component. A remote attacker holding valid authenticated credentials submits crafted XML containing external entity references, which the server's XML parser resolves. Successful exploitation allows the attacker to read local files from the server and potentially trigger server-side requests (SSRF), enabling disclosure of sensitive configuration or credential material that can support further compromise. Any organization running SAP NetWeaver AS Java with the BPM component is affected, with exposure determined by whether such systems are reachable and by the privileges an attacker can obtain. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is undetermined.
What to do: Apply the SAP security note/patch addressing CVE-2016-9563 to SAP NetWeaver AS Java per vendor instructions, as required by the CISA KEV listing. Verify whether your AS Java estate includes the BPM (BC-BMT-BPM-DSK) component and whether those instances are internet-reachable, and review authentication on affected services. As interim mitigation, restrict and monitor authenticated access to the affected component and watch logs for XML parser activity indicative of XXE (unexpected external entity resolution or outbound connections from the application server).
| SAP NetWeaver (Application Server Java, BC-BMT-BPM-DSK / BPM component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver application server java
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N