SAP Knowledge Base Article - Preview

3783878 - Security scan reports vulnerabilities

Symptom

  • Security scan reports vulnerabilities for org.springframework:spring-core version 5.3.43 embedded under com.sap.aii.igw.spring.lib, with scanner expectation for version 5.3.49.
  • The finding persists after applying a Java stack patch, including an update of component SAP_XIAF.
  • Reported CVE identifiers include: CVE-2026-41855, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41838, CVE-2026-41839, CVE-2026-41850, CVE-2026-41840, CVE-2026-41851, CVE-2026-41841, CVE-2026-41852, CVE-2026-41842, CVE-2026-41853, CVE-2026-41843, CVE-2026-41844.


Read more...

Environment

  • Integration Gateway
  • SAP NetWeaver 7.5
  • SAP Process Integration / Process Orchestration

Keywords

spring core, springframework, com.sap.aii.igw.spring.lib, integration gateway, PI, PO, NetWeaver 7.5, CVE, security scan, vulnerability, cloud integration content, CIC, SAP_XIAF, AS Java, jar version 5.3.43 , KBA , BC-XI-IGW , Integration Gateway , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.