← Retour
CVE-2026-76958
high
CVSS 8.5
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML pa...
Résumé
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the at...
Résumé IA openai / gpt-4o
SAP Integration Suiteは、信頼できないソースから受け取ったXMLドキュメントを十分に検証していない。この欠陥により、低権限の攻撃者が特別に細工されたXMLペイロードを送信し、サーバー上の機密ファイル内容を読み取る可能性がある。
❓ Quel est le problème
SAP Integration Suiteにおいて、信頼できないソースからのXMLドキュメントの検証が不十分である問題。
📍 Périmètre concerné
SAP Integration Suiteの内部コンポーネント。
🔥 Gravité
攻撃者が機密情報を抽出し、リソースを枯渇させる可能性があるため、機密性に高い影響を与え、可用性にも低い影響を与える。
🔧 Comment corriger
SAPが提供する公式パッチを適用する。
🛡️ Contournement
信頼できるソースからのみXMLドキュメントを受け入れるように設定変更を行う。
🔍 Détection
XMLペイロードの異常な動作を検出する監視を強化する。
Références
- web cna@sap.com
- web cna@sap.com