Impact
SAP Approuter incorrectly verifies client certificates in certain callback flows, allowing an attacker with low privileges who holds a certificate from the same trusted authority and matching subject values to circumvent the identity check. This flaw, identified as CWE-295, can lead to the attacker impersonating a trusted internal component. The exploitation primarily threatens the integrity of the environment, while the impact on confidentiality and availability remains low.
Affected Systems
SAP Business AI Platform (Approuter) from SAP. No specific affected version information is provided; any installation that uses the vulnerable callback flow logic is potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score is not available, suggesting limited publicly known exploitation data. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to craft a callback using a valid certificate with matching subject values from the same certificate authority. Though the attack requires moderate complexity and specific conditions, successful exploitation allows an attacker to impersonate trusted components, posing a significant integrity risk.
OpenCVE Enrichment