BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
| Software | From | Fixed in |
|---|---|---|
| sap / netweaver_application_server_java | 7.50 | 7.50.x |