SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability. | |
| Title | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution) | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-04-22T18:25:55.117Z
Updated: 2025-04-23T15:58:47.132Z
Reserved: 2025-03-27T23:02:06.906Z
Link: CVE-2025-31328
Updated: 2025-04-22T19:03:33.165Z
Status : Awaiting Analysis
Published: 2025-04-22T19:15:52.570
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-31328
No data.
ReportizFlow