PT-2021-17552 · Sap · Sap Process Integration

Published

2021-05-11

·

Updated

2021-08-27

·

CVE-2021-27617

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP Process Integration versions 7.10 through 7.50
Description The issue arises from insufficient validation of an XML document uploaded from a local source by the Integration Builder Framework. This can be exploited by an attacker crafting a malicious XML document. When the application uploads and parses this document, it could lead to denial-of-service conditions due to excessive system memory consumption, significantly impacting system availability.
Recommendations For versions 7.10 through 7.50, update the Integration Builder Framework to a version that properly validates XML documents uploaded from local sources to prevent denial-of-service conditions.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27617

Affected Products

Sap Process Integration