← 戻る
Webアプリケーション
CVE-2026-76958 high CVSS 8.5

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML pa...

概要

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the at...

AI要約 openai / gpt-4o

SAP Integration Suiteは、信頼できないソースから受け取ったXMLドキュメントを十分に検証していない。この欠陥により、低権限の攻撃者が特別に細工されたXMLペイロードを送信し、サーバー上の機密ファイル内容を読み取る可能性がある。
❓ 何が問題か
SAP Integration Suiteにおいて、信頼できないソースからのXMLドキュメントの検証が不十分である問題。
📍 影響範囲
SAP Integration Suiteの内部コンポーネント。
🔥 重要度
攻撃者が機密情報を抽出し、リソースを枯渇させる可能性があるため、機密性に高い影響を与え、可用性にも低い影響を与える。
🔧 修正方法
SAPが提供する公式パッチを適用する。
🛡️ 暫定回避
信頼できるソースからのみXMLドキュメントを受け入れるように設定変更を行う。
🔍 検知方法
XMLペイロードの異常な動作を検出する監視を強化する。

参照URL

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →