Impact
The vulnerability is a missing cross-site request forgery (CSRF) protection in the SAP Approuter authentication flow, classified as CWE-352. This flaw allows an unauthenticated attacker to craft a malicious link and trick a human user into following it. If successful, the attacker can bind the victim's session to an attacker‑controlled identity, effectively hijacking the session. The resulting impact is low‑level integrity compromise for the victim, with no impact on confidentiality or availability.
Affected Systems
SAP Business AI Platform (Approuter) from SAP SE is affected; no specific version information is disclosed in the CVE data.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑medium severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is that an unauthenticated attacker crafts a malicious link and lures a legitimate user into clicking it, exploiting the lack of CSRF checks to bind the user's session to the attacker's identity. No special conditions are required beyond the victim visiting the link.
OpenCVE Enrichment