First published: Tue Feb 11 2025(Updated: )
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Approuter | <v16.7.1 | |
npm/@sap/approuter | >=2.6.1<16.7.2 | 16.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24876 is classified as a High severity vulnerability due to its potential impact on confidentiality and integrity.
To fix CVE-2025-24876, upgrade the SAP Approuter Node.js package to a version later than v16.7.1.
Exploiting CVE-2025-24876 allows attackers to bypass authentication and potentially steal sessions from victims.
SAP Approuter version v16.7.1 and earlier are affected by CVE-2025-24876.
Currently, there are no widely recognized workarounds for CVE-2025-24876; updating to a fixed version is the recommended approach.