XML External Entity Injection in Integration Suite
SAP Integration Suite
XXE in an integration middleware is particularly dangerous because Integration Suite typically holds credentials and endpoints across your entire landscape — ERP, third-party systems, partner portals. If exploited for SSRF, an attacker could pivot into systems that trust the Integration Suite IP. Most BTP customers receive this automatically via SAP-managed updates, but verify.
Vulnerability Detail
Insufficient XML validation in SAP Integration Suite components allows XML External Entity (XXE) injection. An attacker could read sensitive files from the integration server, initiate server-side requests, or disrupt XML processing.
Patch Action
Apply the patch per SAP Note 3792978 to the Integration Suite tenant. Verify with your BTP administrator that the update has been applied. Verify affected versions in the official SAP Note.
Patch Info