Impact
WebSocket connections in SAP Business AI Platform’s Approuter lack proper authorization checks in specific operations. An attacker with low privileges may invoke these operations to read secret data and alter limited settings. The failure exposes sensitive information, leading to a high confidentiality impact, while changes to data integrity are low and availability is unaffected. This weakness maps to Missing Authorization (CWE‑862).
Affected Systems
The vulnerability affects SAP Business AI Platform (Approuter) environments that expose WebSocket endpoints. No specific product versions are listed, so all installations of Approuter using the affected functionality are potentially at risk. The impacted vendor is SAP SE.
Risk and Exploitability
With a CVSS score of 5.9 the vulnerability is moderate in severity. The EPSS score is not available; however, the risk remains limited because exploitation requires authenticated access with low privileges, and the privileged impact is confined to confidentiality. It is not listed in the CISA KEV catalog. Attackers would typically use a normal user account to exploit the mis‑authorization via WebSocket, read secrets, and make restrained modifications.
OpenCVE Enrichment