Executive brief
SAP Process Integration's SOAP Adapter component can be exploited by privileged users to send malicious requests that consume excessive processor resources. An attacker with administrative access can temporarily degrade system performance and responsiveness, impacting business operations and user access to critical integration services.
Technical details
The vulnerability exists in the SOAP Adapter component of SAP Process Integration, where deeply nested entity definitions in specially crafted requests trigger excessive CPU consumption. Attack requires high privilege level (authenticated administrative user) and network access to the SOAP endpoint. Successful exploitation causes temporary processor load increase and system responsiveness degradation, resulting in low availability impact. No confidentiality or integrity compromise occurs. Patch availability is expected via SAP Security Patch Day; refer to SAP Note 3736494 for mitigation details.
Affected products
- SAP Process Integration <UNKNOWN>
Timeline
- 2026-09-08: disclosed