PT-2025-6125 · Sap · Sap Erp+1

Published

2025-02-11

·

Updated

2025-02-11

·

CVE-2025-23191

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SAP ERP (affected versions not specified)
Description: The issue concerns the SAP OData endpoint in SAP Fiori for SAP ERP, where cached values could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the atom:link values in the returned metadata, redirecting them from the SAP server to a malicious link. This could cause low impact on the integrity of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-02755
CVE-2025-23191

Affected Products

Sap Erp
Sap Fiori