CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
- Affected products
- Sap Netweaver As Java
- Sap Netweaver Application Server Java
- ≤ 7.50
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 15.1% (96th percentile)
- Weakness
- CWE-611
- NVD status
- Modified
- Published
- 2016-04-07
CVE-2016-3974 at NVD
4 known exploits for CVE-2016-3974
Proof-of-concept code and exploit modules indexed by Sploitus