SAP

Approuter

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 00:19:50
  • Zuletzt bearbeitet 08.09.2026 20:21:52

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This resul...

  • EPSS 0.31%
  • Veröffentlicht 11.08.2026 00:19:41
  • Zuletzt bearbeitet 08.09.2026 20:20:05

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass a...

  • EPSS 0.14%
  • Veröffentlicht 11.08.2026 00:19:30
  • Zuletzt bearbeitet 08.09.2026 20:21:54

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and load...

  • EPSS 0.12%
  • Veröffentlicht 11.08.2026 00:19:20
  • Zuletzt bearbeitet 08.09.2026 20:20:09

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacke...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 00:19:10
  • Zuletzt bearbeitet 08.09.2026 20:22:16

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's c...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 00:17:38
  • Zuletzt bearbeitet 08.09.2026 20:20:15

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availabilit...

  • EPSS 0.12%
  • Veröffentlicht 11.08.2026 00:17:28
  • Zuletzt bearbeitet 08.09.2026 20:22:13

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This comple...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 00:15:40
  • Zuletzt bearbeitet 08.09.2026 20:20:20

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation co...

  • EPSS 0.26%
  • Veröffentlicht 11.08.2026 00:15:29
  • Zuletzt bearbeitet 08.09.2026 20:22:11

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime co...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 00:12:54
  • Zuletzt bearbeitet 08.09.2026 20:20:28

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sens...