Executive brief
SAP Approuter, a component that manages authentication and routing for SAP applications, fails to properly validate client certificates during certain callback operations. An attacker with a certificate from the same trusted authority could impersonate legitimate internal components, potentially gaining unauthorized access to protected systems and compromising system integrity.
Technical details
This is an authentication bypass vulnerability in SAP Approuter's client certificate validation logic during callback flows. The vulnerability stems from insufficient validation of certificate subject values, allowing an attacker holding a validly-signed certificate from the same trusted certificate authority to bypass identity verification. The attack requires the attacker to already possess a certificate from the same trusted CA with matching subject fields, making exploitation moderately difficult. Successful exploitation allows impersonation of trusted internal components, compromising system integrity. A patch is available via SAP Security Note 3786038.
Affected products
- SAP Approuter
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: SAP Security Note 3786038