Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44745

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

EPSS

Процентиль: 26%
0.00331
Низкий

8.1 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.1
github
19 дней назад

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

CVSS3: 8.1
fstec
19 дней назад

Уязвимость node.js-библиотеки SAP Approuter, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.00331
Низкий

8.1 High

CVSS3

Дефекты

CWE-601