4.3

CVE-2026-66761

Multiple vulnerabilities in SAP Business AI Platform (Approuter)

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Approuter SwPlatform node.js Version < 23.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.127
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://url.sap/sapsecuritypatchday
Vendor Advisory
https://me.sap.com/notes/3786038
Permissions Required