Impact
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests with deeply nested entity definitions that can temporarily increase processor load and degrade system responsiveness. The result is a modest availability outage with no effects on confidentiality or integrity. The weakness is a form of input handling that exceeds resource limits, identified as CWE-776.
Affected Systems
The affected product is SAP Process Integration, specifically the SOAP Adapter component. No version information is provided.
Risk and Exploitability
The CVSS score of 2.2 reflects low severity, and the EPSS score is unavailable, suggesting limited exploitation likelihood. It is not catalogued in the CISA KEV list. The vulnerability requires a privileged user—either local or with access to the SOAP interface—making the attack vector likely limited to internal or authorized users who can craft the malicious requests.
OpenCVE Enrichment