Back

MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)

Published Apr 22, 2025

Description

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner sap
Published Apr 22, 2025
Updated Apr 23, 2025
Reserved Mar 27, 2025

CISA Vulnrichment

Updated Apr 22, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner sap
Published Apr 22, 2025
Updated Apr 23, 2025

GitHub

No data