SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute.
This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Sap Approuter
cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:*
|
— |
23.0.0
|