Description
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 11 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. | |
| Title | Multiple vulnerabilities in SAP Business AI Platform (Approuter) | |
| Weaknesses | CWE-644 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-08-11T00:19:50.954Z
Reserved: 2026-07-27T17:33:56.949Z
Link: CVE-2026-66778
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax