Symptom
- Security scan reports vulnerabilities for org.springframework:spring-core version 5.3.43 embedded under com.sap.aii.igw.spring.lib, with scanner expectation for version 5.3.49.
- The finding persists after applying a Java stack patch, including an update of component SAP_XIAF.
- Reported CVE identifiers include: CVE-2026-41855, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41838, CVE-2026-41839, CVE-2026-41850, CVE-2026-41840, CVE-2026-41851, CVE-2026-41841, CVE-2026-41852, CVE-2026-41842, CVE-2026-41853, CVE-2026-41843, CVE-2026-41844.
Read more...
Environment
- Integration Gateway
- SAP NetWeaver 7.5
- SAP Process Integration / Process Orchestration
Keywords
spring core, springframework, com.sap.aii.igw.spring.lib, integration gateway, PI, PO, NetWeaver 7.5, CVE, security scan, vulnerability, cloud integration content, CIC, SAP_XIAF, AS Java, jar version 5.3.43 , KBA , BC-XI-IGW , Integration Gateway , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview