Impact
The vulnerability arises from inconsistent error handling in SAP Approuter, classified as an Improper Handling of Exceptions (CWE-754). An attacker with only low privileges can potentially trigger exploitation if the system is configured non‑normally. Successful exploitation is highly complex because it relies on external conditions beyond the attacker’s control and would only degrade service availability; confidentiality and integrity remain unaffected.
Affected Systems
Affected systems are those running SAP Business AI Platform with the Approuter component, as cataloged under SAP SE. No specific product versions are listed in the advisory, so any installation that uses a non‑default startup configuration potentially remains vulnerable until patched.
Risk and Exploitability
The CVSS score is 3.7 indicating low severity. EPSS data is not available and the vulnerability is not in the CISA KEV list. Given the required context, the attack vector likely needs low‑privilege access to the Approuter and depends on configuration quirks. Because the conditions for successful exploitation are complex and externally influenced, the overall risk to the environment is low, yet monitoring for degraded availability is recommended.
OpenCVE Enrichment