CyberRota
Live Feed
Return to register
Case File

CVE-2016-9563

MEDIUM · CVSS 6.5 EPSS 23.80% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-11-23 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Cross-Reference — CISA KEV

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2021-11-03

Required action: Apply updates per vendor instructions.

CVE
CVE-2016-9563
Severity
MEDIUM
CVSS
6.5
EPSS
23.80%
Java

Original Filing — NVD Description

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.