Lucene search

K
cvelistMitreCVELIST:CVE-2016-3974
HistoryApr 07, 2016 - 7:00 p.m.

CVE-2016-3974

2016-04-0719:00:00
mitre
www.cve.org

9.1 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%

XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.

9.1 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%