Vulnerabilities/

Unauthorized access to data in @sap-cloud-sdk/core

Severity:
Medium

Description

This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations. In some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions. By default, destination caching is disabled.

Recommendation

Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sap-cloud-sdk/core
Anything's wrong? Let us know Last updated on February 01, 2023