CVE-2026-58234 PUBLISHED

Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)

Assigner: sap
Reserved: 29.06.2026 Published: 08.09.2026 Updated: 08.09.2026

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 2.2

Product Status

Vendor SAP_SE
Product SAP Process Integration (SOAP Adapter)
Versions Default: unaffected
  • Version MESSAGING 7.50 is affected
  • Version SAP_XIAF 7.50 is affected

References

Problem Types