CVE-2016-3974: SAP NetWeaver Application Server Java
Critical severity, CVSS 9.1. EPSS: 15.1% chance of exploitation in the next 30 days.
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
Affected products
- SAP NetWeaver Application Server Java: from 7.10, up to and including 7.50
Published 2016-04-07. Last modified 2026-06-17.