PT-2025-6134 · Sap · Sap Approuter Node.Js
Published
2025-02-11
·
Updated
2025-03-24
·
CVE-2025-24876
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Approuter Node.js package versions 2.6.1 through 16.7.1
Description:
The issue concerns an authentication bypass vulnerability. When trading an authorization code, an attacker can steal the session of the victim by injecting malicious payload, causing high impact on confidentiality and integrity of the application.
Recommendations:
For SAP Approuter Node.js package versions 2.6.1 through 16.7.1, consider updating to a version later than 16.7.1 to resolve the authentication bypass issue. As a temporary workaround, restrict access to authorization code trading to minimize the risk of exploitation. Avoid using vulnerable functions related to authorization code trading until the issue is resolved. At the moment, there is no information about additional mitigation measures.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Approuter Node.Js