SAP Approuter Node.js Package Authentication Bypass Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in the SAP Approuter Node.js package, specifically in version 16.7.1 and earlier. This vulnerability allows an attacker to steal a victim's session by injecting malicious payloads while exchanging an authorization code. The issue arises from a flaw in the authorization code handling process, leading to a high impact on the application's confidentiality and integrity.
Impact
Exploitation of this vulnerability could result in unauthorized access to user sessions, allowing attackers to impersonate victims and potentially manipulate application data or functionality.
Remediation
Users are advised to update to version 20.5.1 or later. For guidance on implementing this update, refer to the SAP Security Notes available in SAP for Me.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
