Impact
SAP Approuter fails to enforce integrity checks on certain session‐related request headers under specific conditions. An attacker with low privileges can craft a request that bypasses these checks and injects another user’s session context. The compromise primarily threatens confidentiality, allowing the attacker to view data belonging to other users, while the impact on integrity is low and there is no effect on availability.
Affected Systems
The vulnerability affects SAP Business AI Platform (Approuter) from SAP_SE. No specific product version information is provided in the CNA data.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no current widespread exploitation. Successful exploitation requires an attacker to have a low‑privilege foothold and to have previously observed matching session values out‑of‑band, which makes the attack complex. Based on the description, it is inferred that the attack originates from within the environment where session headers can be monitored, and that it relies on bypassing integrity checks rather than exploiting a direct code execution or denial of service path.
OpenCVE Enrichment