CVE-2026-58234

Summary

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP Process Integration (SOAP Adapter)MESSAGING 7.50affected
SAP_SESAP Process Integration (SOAP Adapter)SAP_XIAF 7.50affected

Weaknesses

  • CWE-776: CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

References