PT-2026-57948 · Sap · Sap Change/Transport System Attach Tool
CVE-2026-58233
·
Published
2026-07-14
·
Updated
2026-07-16
CVSS v2.0
8.7
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
SAP Change and Transport System Attach Tool (ctsattach) (affected versions not specified)
Description
An authenticated attacker can provide a specially crafted archive file that triggers insecure deserialization when processed by the application library. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code. This can lead to remote code execution (RCE), allowing the attacker to extract sensitive information and gain control over the system and its processes.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict archive processing to minimize the risk of exploitation.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Change/Transport System Attach Tool