Impact
SAP Approuter fails to fully validate token contents under certain configurations, allowing an unauthenticated attacker to send a crafted token that can cause the system to send sensitive credential material to an attacker-controlled destination. This flaw results in a high confidentiality impact while having only a minor influence on integrity and availability.
Affected Systems
SAP Business AI Platform (Approuter) is affected. The flaw is present in all deployment versions of this product that have the default token validation configuration enabled. No specific product versions are listed, so any instance where the vulnerable token processing path is active is at risk.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. Exploitation requires non-default preconditions, implying a high attack complexity and that the attacker must first identify an environment with the specific configuration that allows the vulnerability. The EPSS score is not available, and the vulnerability is not listed in KEV, suggesting no widespread public exploitation yet. Nevertheless, the potential for an unauthenticated attacker to exfiltrate credential data makes timely remediation essential.
OpenCVE Enrichment