Impact
The vulnerability exists because SAP Approuter does not enforce sufficient flow control in certain functions, allowing an attacker with low privileges to send large volumes of data without receiving responses. This causes unbounded memory growth, leading to a low impact on availability. Confidentiality and integrity are not affected.
Affected Systems
The affected product is SAP Business AI Platform (Approuter) from SAP SE. No specific version information is provided.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower current exploitation likelihood. The attack vector likely involves an attacker who has some level of access to the Approuter to send large data payloads, exploiting the lack of flow control.
OpenCVE Enrichment