Impact
The SAP Approuter component fails to handle certain requests when specific runtime conditions are present. An attacker who does not need authentication can send crafted input that triggers a crash and forced restart. Successful exploitation strictly depends on meeting those runtime conditions, making the attack more complex than a simple request. The result is a denial of service that impacts availability; there is no effect on confidentiality or integrity.
Affected Systems
SAP Business AI Platform (Approuter) from SAP SE. No specific version information is provided.
Risk and Exploitability
The CVSS score of 5.9 places this vulnerability in the moderate range. The EPSS score is not available, so overall likelihood cannot be quantified, but the attack requires precise runtime conditions and the component lacks authentication, making the exploitation path nontrivial. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits are documented. The primary risk is that a successful exploit would cause a service interruption through repeated crashes and restarts, potentially leading to extended downtime if attackers time the attacks to coincide with critical processing windows.
OpenCVE Enrichment