Cached values belonging to the SAP OData endpoint in SAP...
Low severity
Unreviewed
Published
Feb 11, 2025
to the GitHub Advisory Database
•
Updated Feb 11, 2025
Description
Published by the National Vulnerability Database
Feb 11, 2025
Published to the GitHub Advisory Database
Feb 11, 2025
Last updated
Feb 11, 2025
Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the
atom:link
values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application.References