Vulnerabilities/

Authentication bypass in @sap/approuter

Severity:
High

Description

The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code, an attacker can steal the session of the victim by injecting malicious payload, causing High impact on confidentiality and integrity of the application.

Recommendation

Update the @sap/approuter package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sap/approuter
Anything's wrong? Let us know Last updated on February 11, 2025