CVE-2016-4014
XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.
- Affected products
- Sap Netweaver As Java
- Sap Netweaver
- = 7.4
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.6 HIGH
- EPSS
- 5.3% (92th percentile)
- NVD status
- Modified
- Published
- 2016-04-14
CVE-2016-4014 at NVD
1 known exploit for CVE-2016-4014
Proof-of-concept code and exploit modules indexed by Sploitus