CVE-2025-24876

HIGH

SAP Approuter Node.js <v16.7.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application

Scores

CVSS v3 8.1
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287 CWE-302
Status published
Products (2)
sap/approuter 2.6.1 - 16.7.2npm
SAP_SE/SAP Approuter Node.js package 2.6.1 to 16.7.1
Published Feb 11, 2025
Tracked Since Feb 18, 2026