GHSA-44p5-3m5g-vfhjHighCVSS 8.1
SAP Approuter has an Open Redirect vulnerability
🔗 CVE IDs covered (1)
📋 Description
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.
🎯 Affected products1
- npm/@sap/approuter:< 21.2.0