PT-2025-6134 · Sap · Sap Approuter Node.Js

Published

2025-02-11

·

Updated

2025-03-24

·

CVE-2025-24876

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SAP Approuter Node.js package versions 2.6.1 through 16.7.1
Description: The issue concerns an authentication bypass vulnerability. When trading an authorization code, an attacker can steal the session of the victim by injecting malicious payload, causing high impact on confidentiality and integrity of the application.
Recommendations: For SAP Approuter Node.js package versions 2.6.1 through 16.7.1, consider updating to a version later than 16.7.1 to resolve the authentication bypass issue. As a temporary workaround, restrict access to authorization code trading to minimize the risk of exploitation. Avoid using vulnerable functions related to authorization code trading until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24876
GHSA-CPFX-964W-4JVP

Affected Products

Sap Approuter Node.Js