Executive brief
SAP Approuter is a routing and authentication component used in SAP's cloud application architecture. An attacker with low privileges can exploit insufficient flow control by sending large volumes of data without consuming responses, causing the system to accumulate unbounded memory and degrading availability. Attackers cannot access sensitive data or modify systems, but can launch denial-of-service attacks against affected deployments.
Technical details
The vulnerability is a flow control bypass in SAP Approuter. The root cause is insufficient enforcement of flow control mechanisms in certain functionality, allowing an authenticated attacker to send high volumes of data without properly consuming responses. This causes unbounded memory growth on the affected service. The attack requires low privileges and network access to the Approuter. An attacker can degrade or exhaust service availability through a denial-of-service condition. SAP has released a security patch as part of their monthly security patch day on August 11, 2026.
Affected products
- SAP Approuter
Timeline
- 2026-08-11: advisory: SAP Security Patch Day publication
- 2026-08-11: patched