Impact
A server-controlled __next URL that does not enforce cross‑origin checks can allow a malicious or compromised OData service to expose sensitive authentication information, resulting in a high impact on confidentiality. The attack does not affect data integrity and does not disrupt availability. The weakness is identified as a common mistake in handling redirects (CWE‑601).
Affected Systems
SAP products using the OData service are affected. The CNA lists the product identifier SAP_SE:Odata. No specific version information is supplied, so all current and past releases of SAP OData could be vulnerable until a patch is applied.
Risk and Exploitability
The severity score of 5.9 indicates a moderate risk level. The EPSS score is not available, but the lack of a KEV listing suggests that widespread exploitation has not yet been reported. Attackers can potentially exploit the flaw by crafting a malicious OData request that includes a __next parameter pointing to an external origin, causing the service to leak credentials to that origin. A successful exploitation would enable information disclosure to an attacker or a compromised service, but would not lead to code execution, modify data, or deny service. Organizations should treat this as a medium‑risk vulnerability that requires timely mitigation.
OpenCVE Enrichment