Impact
The vulnerability lies in SAP Approuter's inadequate sanitization of certain request headers that are forwarded to internal components. An unauthenticated attacker can craft a request with malicious header values to obtain limited unauthorized access to information. The impact is a low level breach of confidentiality, with no compromise to integrity or availability reported.
Affected Systems
Vendors and products affected include SAP Business AI Platform (Approuter). Specific versions or version ranges are not disclosed in the available data; administrators should review the referenced SAP notes for detailed version applicability.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the low‑to‑medium risk category. The EPSS score is not available, but the lack of a KEV listing suggests low exploitation activity to date. The attack vector is likely remote, via crafted HTTP requests sent to the Approuter, requiring no authentication. In the absence of existing safeguards, a path exists to extract restricted information from downstream services.
OpenCVE Enrichment