SAP
SAP Approuter: vulnerabilidades y CVE
SAP Approuter tiene 14 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses13
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66778 | Media (5.3) | 0.36% | — | 11 ago 2026 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized… |
| CVE-2026-66777 | Media (5.9) | 0.44% | — | 11 ago 2026 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send… |
| CVE-2026-66776 | Media (5.9) | 0.20% | — | 11 ago 2026 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that… |
| CVE-2026-66775 | Media (4.3) | 0.17% | — | 11 ago 2026 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful… |
| CVE-2026-66774 | Baja (3.7) | 0.35% | — | 11 ago 2026 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on… |
| CVE-2026-66761 | Media (4.3) | 0.38% | — | 11 ago 2026 | SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results… |
| CVE-2026-66760 | Media (6.4) | 0.18% | — | 11 ago 2026 | SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass… |
| CVE-2026-58239 | Baja (3.7) | 0.35% | — | 11 ago 2026 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their… |
| CVE-2026-58238 | Media (5.9) | 0.43% | — | 11 ago 2026 | SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful… |
| CVE-2026-58237 | Media (5.9) | 0.28% | — | 11 ago 2026 | WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could… |
| CVE-2026-58230 | Alta (7) | 0.31% | — | 11 ago 2026 | SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an… |
| CVE-2026-44745 | Alta (8.1) | 0.47% | — | 14 jul 2026 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked… |
| CVE-2026-27690 | Crítica (9.1) | 0.68% | — | 14 jul 2026 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the… |
| CVE-2025-24876 | Alta (8.1) | 0.50% | — | 11 feb 2025 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload… |
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29