Vulnerability record · CVE-2016-9563 · published 23 November 2016
CVE-2016-9563: SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpoint
Sap · Netweaver Application Server Java
The BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI. The flaw is tracked as SAP Security Note 2296909 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants attention despite a medium CVSS score.
Description
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is listed in CISA KEV with a high EPSS percentile, but exploitation requires authenticated access and the CVSS impact is limited to confidentiality.
What it is
The BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI. The flaw is tracked as SAP Security Note 2296909 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants attention despite a medium CVSS score.
Impact
An authenticated attacker can read files accessible to the SAP Java process and potentially reach internal network resources via server-side request forgery. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network through the bpemuwlconn web endpoint; the vector requires low privileges (PR:L) and no user interaction (UI:N). Only remote authenticated users can trigger it.
Exploitation
CVE-2016-9563 is in CISA KEV with a 2021-11-03 addition and a 2022-05-03 remediation due date, and EPSS shows a 30-day probability of 0.238 (97.7th percentile). No public exploit references are tagged in the record, and no ransomware use is documented.
What to do
- Apply the fix per SAP Security Note 2296909; patch NetWeaver AS Java 7.5 to the corrected level.
- If patching is delayed, disable external entity resolution in the XML parser used by the BC-BMT-BPM-DSK component.
- Restrict network access to the bpemuwlconn endpoint to trusted internal clients.
- Review and minimize accounts with access to the affected BPM/DSK functionality.
- Verify the KEV remediation due date is met and track closure.
Detection
- Monitor web logs for requests to sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn with XML bodies containing DOCTYPE or ENTITY declarations.
- Alert on outbound connections from the SAP Java host to unexpected internal or external addresses.
- Audit file access by the SAP Java process for reads of sensitive configuration or system files.
- Correlate authentication events with subsequent requests to the bpemuwlconn URI to spot post-login abuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-9563 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver XML External Entity (XXE) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/92419 | Broken LinkThird Party AdvisoryVDB Entry |
| https://erpscan.io/advisories/erpscan-16-034-sap-netweaver-java-xxe-vulnerability-bc-bmt-bpm-dsk-component/ | Broken LinkThird Party Advisory |
| https://launchpad.support.sap.com/#/notes/2296909 | Permissions Required |
| http://www.securityfocus.com/bid/92419 | Broken LinkThird Party AdvisoryVDB Entry |
| https://erpscan.io/advisories/erpscan-16-034-sap-netweaver-java-xxe-vulnerability-bc-bmt-bpm-dsk-component/ | Broken LinkThird Party Advisory |
| https://launchpad.support.sap.com/#/notes/2296909 | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-9563 | US Government Resource |
Track CVE-2016-9563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-9563), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.