Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-24876
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication bypass via authorization code injection in SAP Approuter
Source: NVD (National Vulnerability Database)
Vulnerability Description
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1287
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP Approuter 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP Approuter是德国思爱普(SAP)公司的一项轻量级服务,可作为 SAP 生态系统中各种后端服务和应用程序的单一入口点。 SAP Approuter v16.7.1版本及之前版本存在输入验证错误漏洞。攻击者利用该漏洞可以通过注入恶意载荷来窃取受害者的会话。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
SAP_SESAP Approuter Node.js package 2.6.1 to 16.7.1 -
II. Public POCs for CVE-2025-24876
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-24876
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-24876

No comments yet


Leave a comment