SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12262 SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
Description SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Title Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-04-23T15:58:47.132Z

Reserved: 2025-03-27T23:02:06.906Z

Link: CVE-2025-31328

cve-icon Vulnrichment

Updated: 2025-04-22T19:03:33.165Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T19:15:52.570

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-31328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses