Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44p5-3m5g-vfhj

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

EPSS

Процентиль: 26%
0.00331
Низкий

8.1 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.1
nvd
19 дней назад

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

CVSS3: 8.1
fstec
19 дней назад

Уязвимость node.js-библиотеки SAP Approuter, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.00331
Низкий

8.1 High

CVSS3

Дефекты

CWE-601