SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Apr 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability. | |
Title | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution) | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-04-22T18:25:55.117Z
Updated: 2025-04-23T15:58:47.132Z
Reserved: 2025-03-27T23:02:06.906Z
Link: CVE-2025-31328

Updated: 2025-04-22T19:03:33.165Z

Status : Awaiting Analysis
Published: 2025-04-22T19:15:52.570
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-31328

No data.