Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
Summary
| CVE | CVE-2026-58234 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-08 01:17:50 UTC |
| Updated | 2026-09-08 01:17:50 UTC |
| Description | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity. |
Risk And Classification
Primary CVSS: v3.1 2.2 LOW from [email protected]
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Problem Types: CWE-776 | CWE-776 CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 2.2 | LOW | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 2.2 | LOW | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP Process Integration SOAP Adapter | affected MESSAGING 7.50 | Not specified |
| CNA | SAP SE | SAP Process Integration SOAP Adapter | affected SAP_XIAF 7.50 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| url.sap/sapsecuritypatchday | [email protected] | url.sap | |
| me.sap.com/notes/3736494 | [email protected] | me.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.