SAP_SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP Business AI Platform (Approuter).
Products
Clear product- SAP BusinessObjects Business Intelligence Platform22 vulnerabilities
- SAP NetWeaver Application Server for ABAP and ABAP Platform16 vulnerabilities
- SAP NetWeaver Application Server ABAP12 vulnerabilities
- SAP NetWeaver Application Server for ABAP12 vulnerabilities
- SAP Business AI Platform (Approuter)11 vulnerabilities
- SAP NetWeaver Application Server ABAP and ABAP Platform10 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform9 vulnerabilities
- SAP Commerce Cloud8 vulnerabilities
- SAP GUI for Windows8 vulnerabilities
- SAP NetWeaver Application Server Java8 vulnerabilities
- SAP Business Connector7 vulnerabilities
- SAP CRM WebClient UI7 vulnerabilities
- SAP Enable Now6 vulnerabilities
- SAP Fiori App (Intercompany Balance Reconciliation)6 vulnerabilities
- SAP NetWeaver Enterprise Portal6 vulnerabilities
- SAP Manufacturing Integration and Intelligence5 vulnerabilities
- SAP Supplier Relationship Management (Live Auction Cockpit)5 vulnerabilities
- SAP Web Dispatcher5 vulnerabilities
- SAP Commerce4 vulnerabilities
- SAP Financial Consolidation4 vulnerabilities
- SAP Host Agent4 vulnerabilities
- SAP NetWeaver4 vulnerabilities
- SAP NetWeaver AS Java4 vulnerabilities
- SAP Solution Manager4 vulnerabilities
- SAPCAR4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66778MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. CWE-644Aug 11, 2026 | CVSS5.3v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66777MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentia… CWE-22Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66776MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a lo… CWE-347Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.138% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66775MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability. CWE-352Aug 11, 2026 | CVSS4.3v3.1 | EPSS0.124% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity. CWE-754Aug 11, 2026 | CVSS3.7v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-66761MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity. CWE-770Aug 11, 2026 | CVSS4.3v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66760MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability. CWE-295Aug 11, 2026 | CVSS6.4v3.1 | EPSS0.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability. CWE-807Aug 11, 2026 | CVSS3.7v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-58238MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity. CWE-770Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58237MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter)WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. CWE-862Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58230HIGH | Multiple vulnerabilities in SAP Business AI Platform (Approuter)SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability. CWE-601Aug 11, 2026 | CVSS7.0v3.1 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |