Description
This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations. In some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions. By default, destination caching is disabled.
Recommendation
Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.52.0
- Patched version(s): 1.52.0
References
Could your website be exposed too?
SmartScanner can check your website for Unauthorized access to data in @sap-cloud-sdk/core and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Authorization in @sap-cloud-sdk/core - Vulnerability
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks - @backstage/plugin-catalog-unprocessed-entities-common - CVE-2026-44374
- Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks - CVE-2026-44374


