← Vulnerability feed

Vulnerability record · CVE-2016-9563 · published 23 November 2016

CVE-2016-9563: SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpoint

Sap · Netweaver Application Server Java

The BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI. The flaw is tracked as SAP Security Note 2296909 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants attention despite a medium CVSS score.

6.5 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 EPSS 24% · top 2.2% CWE-611 · XML external entity (XXE)
6.5CVSS 3.1 base score, v2 4.0
24%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is listed in CISA KEV with a high EPSS percentile, but exploitation requires authenticated access and the CVSS impact is limited to confidentiality.

What it is

The BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI. The flaw is tracked as SAP Security Note 2296909 and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants attention despite a medium CVSS score.

Impact

An authenticated attacker can read files accessible to the SAP Java process and potentially reach internal network resources via server-side request forgery. The CVSS vector shows high confidentiality impact with no integrity or availability effect.

Attack surface

Reachable over the network through the bpemuwlconn web endpoint; the vector requires low privileges (PR:L) and no user interaction (UI:N). Only remote authenticated users can trigger it.

Exploitation

CVE-2016-9563 is in CISA KEV with a 2021-11-03 addition and a 2022-05-03 remediation due date, and EPSS shows a 30-day probability of 0.238 (97.7th percentile). No public exploit references are tagged in the record, and no ransomware use is documented.

What to do

  • Apply the fix per SAP Security Note 2296909; patch NetWeaver AS Java 7.5 to the corrected level.
  • If patching is delayed, disable external entity resolution in the XML parser used by the BC-BMT-BPM-DSK component.
  • Restrict network access to the bpemuwlconn endpoint to trusted internal clients.
  • Review and minimize accounts with access to the affected BPM/DSK functionality.
  • Verify the KEV remediation due date is met and track closure.

Detection

  • Monitor web logs for requests to sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn with XML bodies containing DOCTYPE or ENTITY declarations.
  • Alert on outbound connections from the SAP Java host to unexpected internal or external addresses.
  • Audit file access by the SAP Java process for reads of sensitive configuration or system files.
  • Correlate authentication events with subsequent requests to the bpemuwlconn URI to spot post-login abuse.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-9563 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver XML External Entity (XXE) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-9563 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed10.0CVE-2010-5326SAP NetWeaver Java Invoker Servlet unauthenticated remote code executionThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attacke…KEVEPSS 18%analysed9.8CVE-2016-2386SAP NetWeaver UDDI Server SQL InjectionThe UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command executio…KEVEPSS 72%analysed7.5CVE-2017-12637SAP NetWeaver Java directory traversal allows arbitrary file readSAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attack…KEVEPSS 95%analysed7.5CVE-2016-3976SAP NetWeaver AS Java directory traversal in CrashFileDownloadServletSAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A re…KEVEPSS 47%analysed5.3CVE-2016-2388SAP NetWeaver AS Java Universal Worklist information disclosureThe Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an inform…KEVEPSS 52%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2016-9563), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.