Executive brief
Avantra, an AIOps platform for SAP operations management, contains a vulnerability where user login sessions do not expire correctly. This allows an attacker to capture and reuse a valid session ID to impersonate a legitimate user and gain unauthorized access to the system. Such an exploit could lead to full administrative control over the management platform, potentially impacting the availability and integrity of the managed SAP environment.
Technical details
The vulnerability is classified as CWE-613 (Insufficient Session Expiration) within the Avantra management software. Due to improper session management, session identifiers remain valid longer than intended or can be reused after they should have expired. A remote, unauthenticated attacker can perform a session replay attack if they obtain a valid session ID (typically requiring some user interaction or interception). Successful exploitation allows the attacker to bypass authentication mechanisms and achieve the same privileges as the hijacked session, which, according to the CVSS vector, can lead to a total compromise of confidentiality, integrity, and availability. The issue is resolved in Avantra version 25.3.1.
Affected products
- syslink software AG Avantra before 25.3.1
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
- 2026-06-02: other: NVD analysis updated