Impact
The SAP Approuter fails to properly validate incoming request headers during the OAuth2 login flow, allowing an unauthenticated attacker to craft a malicious URL that redirects a victim to an arbitrary destination. Successful exploitation can lead the victim’s session to the attacker’s control and grant unauthorized access, compromising confidentiality and integrity of the target application. Availability is not affected by this flaw.
Affected Systems
SAP Approuter is affected. All releases that use the described OAuth2 configuration are potentially impacted, though no specific version numbers are provided.
Risk and Exploitability
The CVSS score of 8.1 classifies this defect as high severity, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker who successfully creates a crafted redirect link can cause a victim to be directed to a page under the attacker’s control, thereby gaining unauthorized access to the victim’s session and data. The impact on confidentiality and integrity is significant, whereas availability remains unchanged.
OpenCVE Enrichment