CVE-2025-24876
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 302
CWE ID 1287
Summary
CVE-2025-24876 is a newly disclosed vulnerability affecting the SAP Approuter Node.js package. Version 16.7.1 and earlier are vulnerable to authentication bypass. During the authorization code trading process, an attacker can inject malicious payload to steal the victim's session, leading to a high-impact breach of confidentiality and integrity for the affected application. Organizations utilizing these impacted versions of SAP Approuter should prioritize patching or implementing alternative security measures to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share