Impact
SAP Approuter fails to properly validate tenant context in inbound requests. An unauthenticated attacker can send crafted requests that spoof another tenant’s context, potentially gaining limited access to that tenant’s data. This condition results in a low confidentiality impact. The vulnerability does not affect integrity or availability.
Affected Systems
The vulnerability affects SAP Business AI Platform (Approuter). No specific product versions are listed in the available data, so any deployment of this platform could be at risk.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity. EPSS data is not published, and the vulnerability is not listed in CISA KEV, implying no known exploits. The likely attack vector involves direct network traffic to the Approuter, requiring no prior authentication. Since the exploitation grants only limited access to another tenant’s information, the overall risk is modest, but it remains relevant for environments with multi‑tenant configurations.
OpenCVE Enrichment