Impact
The vulnerability arises from HTTP request smuggling in SAP Approuter. An unauthenticated attacker can send a specially crafted HTTP request that induces request‑response desynchronization. This can expose user responses, compromising confidentiality, and disrupt normal operation, raising availability concerns.
Affected Systems
SAP Approuter components provided by SAP SE. No specific version range is detailed in the advisory.
Risk and Exploitability
CVSS score of 9.1 indicates very high severity. EPSS < 1% suggests low current exploitation probability. The issue is not listed in CISA KEV, so active exploitation risk depends on the presence of unauthenticated interfaces. The flaw can be exploited over the network via standard HTTP, requiring no authentication.
OpenCVE Enrichment