PT-2021-23215 · Sap · @Sap-Cloud-Sdk/Core

Johenning

+1

·

Published

2021-11-05

·

Updated

2021-11-15

·

CVE-2021-41251

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @sap-cloud-sdk/core versions prior to 1.52.0
Description The issue affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and have enabled caching of destinations. In some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions. By default, destination caching is disabled. If it is enabled, the maximum lifetime is 5 minutes, which limits the attack vector.
Recommendations For versions prior to 1.52.0, update to version 1.52.0 to resolve the issue. As a temporary workaround for users unable to upgrade, disable destination caching, as it is disabled by default.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41251
GHSA-GP2F-254M-RH32

Affected Products

@Sap-Cloud-Sdk/Core