- EPSS 0.24%
- Veröffentlicht 11.08.2026 00:12:16
- Zuletzt bearbeitet 08.09.2026 20:22:08
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination...
CVE-2026-44745
- EPSS 0.33%
- Veröffentlicht 14.07.2026 00:18:16
- Zuletzt bearbeitet 08.09.2026 20:20:34
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unaut...
CVE-2026-27690
- EPSS 0.69%
- Veröffentlicht 14.07.2026 00:17:55
- Zuletzt bearbeitet 08.09.2026 20:22:05
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause t...