Impact
SAP Integration Suite accepts XML documents without sufficient validation in certain internal components, allowing an attacker with low privileges to inject malicious external entity declarations. If exploited, the attacker can read sensitive files from the server, as the payloads are processed and their contents may be exposed through monitoring or logging outputs. This scenario results in a high confidentiality impact; resource exhaustion may occur but its availability impact is low, and there is no effect on integrity.
Affected Systems
SAP SE’s SAP Integration Suite is affected. No specific version information is disclosed in the advisory, so all current releases that contain the vulnerable internal components should be considered at risk.
Risk and Exploitability
The CVSS score of 8.5 positions this flaw in the high severity range, and the lack of an official EPSS score or KEV listing means we cannot quantify current exploitation probability, but the possibility of remote exploitation for file disclosure suggests a non‑negligible attack surface. The likely attack vector involves a remote actor submitting crafted XML via a low‑privilege channel that still has access to the vulnerable component, implying that internal users or services with limited rights could launch the attack.
OpenCVE Enrichment