← Back to browse · API

CVE-2016-9563

Severity
MEDIUM
CVSS
6.5
EPSS
0.23805
Risk score
59.33
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2016-10369, GHSA-PQG2-Q88Q-5H4P
Products
SAP:NetWeaver, n/a:n/a n/a
Sources
euvd EUVD-2016-10369
cisa.gov CVE-2016-9563

Description

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

References