SAP Knowledge Base Article - Public

3701265 - Is Learning affected by CVE-2025-66516 Apache Tika XML External Entity (XXE) Vulnerability?

Symptom

Inquiry regarding whether SAP SuccessFactors Learning (LMS) is affected by CVE-2025-66516 Apache Tika XML External Entity (XXE) Vulnerability.

Environment

SAP SuccessFactors Learning

Resolution

SAP is aware of vulnerability CVE-2025-66516. As of January 7, 2026, SAP has found no evidence of any unauthorized access to customer data or SAP solutions (including SuccessFactors LMS), from this vulnerability.

Keywords

CVE-2025-66516, Apache Tika XML, External Entity, Vulnerability, SAP SuccessFactors Learning , KBA , LOD-SF-LMS-PSI , Security , How To

Product

SAP SuccessFactors Learning 2505