Executive brief
SAP Approuter, a component that routes and manages traffic to internal enterprise applications, fails to properly sanitize certain HTTP request headers before forwarding them. An unauthenticated attacker could exploit this to obtain limited unauthorized access to sensitive information without requiring valid credentials. The vulnerability has low confidentiality impact but does not affect system availability or data integrity.
Technical details
The vulnerability is a header sanitization bypass in SAP Approuter where certain request headers are not sufficiently cleaned before being forwarded to backend services. An unauthenticated, network-based attacker can craft a specially crafted HTTP request with malicious headers to bypass security controls and gain unauthorized access to limited information. The attack requires no authentication, user interaction, or privileged access. The impact is limited to confidentiality (unauthorized information disclosure), with no integrity or availability concerns. Patches are available via SAP Security Notes.
Affected products
- SAP Approuter
Timeline
- 2026-08-11: disclosed