The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
History

Tue, 18 Feb 2025 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601

Tue, 18 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1287
CWE-302

Tue, 11 Feb 2025 06:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
Title Authentication bypass via authorization code injection in SAP Approuter
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-02-21T16:46:32.934Z

Reserved: 2025-01-27T08:57:48.546Z

Link: CVE-2025-24876

cve-icon Vulnrichment

Updated: 2025-02-11T05:45:00.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T01:15:11.887

Modified: 2025-02-18T20:15:31.713

Link: CVE-2025-24876

cve-icon Redhat

No data.