CVE-2016-9563 is an XML External Entity (XXE) vulnerability affecting SAP NetWeaver AS JAVA 7.5, allowing remote authenticated users to conduct XXE attacks via a specific URI. This medium-severity vulnerability has a CVSS score of 6.5, indicating a network-based attack requiring low privileges, with high impact on confidentiality. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog and mentions in community discussions, despite no public exploit code being readily available through Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered significant media coverage, highlighting its importance to SAP application security.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.50CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.