Impact
The vulnerability resides in the @sap/cds-mtxs NPM library used by multitenant applications built with SAP Cloud Application Programming Model (CAP). The library fails to perform sufficient validation on certain functionality when extensibility is enabled, allowing an unauthenticated attacker to craft requests that reveal sensitive credentials. With these credentials, the attacker can then overwrite or delete tenant data, resulting in significant availability and integrity loss for the application, and partial compromise of business data confidentiality.
Affected Systems
SAP Cloud Application Programming Model (CAP) deployments that include the @sap/cds-mtxs library and have the extensibility feature enabled in a multitenant configuration are impacted. No specific version ranges are listed, so any installation utilizing this combination of components is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.4 identifies the issue as critical. EPSS data is not available, and the vulnerability is not included in CISA's KEV catalog. The likely attack vector is an unauthenticated POST or GET request to the vulnerable CAP endpoint, exploiting insufficient input checks. Successful exploitation requires no credentials and can be performed through the public API surface of the application. The high severity and lack of mitigation controls mean the risk remains elevated until a patch is applied.
OpenCVE Enrichment