SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
History

Wed, 23 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
Description SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.
Title Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-04-22T18:25:55.117Z

Updated: 2025-04-23T15:58:47.132Z

Reserved: 2025-03-27T23:02:06.906Z

Link: CVE-2025-31328

cve-icon Vulnrichment

Updated: 2025-04-22T19:03:33.165Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T19:15:52.570

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-31328

cve-icon Redhat

No data.