CVE-2025-23191
Last modified
CVE-2025-23191 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-23191?
How severe is CVE-2025-23191?
How do I fix CVE-2025-23191?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-23186In certain conditions, SAP NetWeaver Application Server ABAP…8.5
- CVE-2025-23187Due to missing authorization check in an RFC enabled functio…5.3
- CVE-2025-23188An authenticated user with low privileges can exploit a miss…4.3
- CVE-2025-23189Due to missing authorization check in an RFC enabled functio…4.3
- CVE-2025-2319The EZ SQL Reports Shortcode Widget and DB Backup plugin for…8.8
- CVE-2025-23190Due to missing authorization check, an authenticated attacke…4.3
- CVE-2025-23192SAP BusinessObjects Business Intelligence (BI Workspace) all…7.6
- CVE-2025-23193SAP NetWeaver Server ABAP allows an unauthenticated attacker…7.5
- CVE-2025-23194SAP NetWeaver Enterprise Portal OBN does not perform proper …5.3
- CVE-2025-23195An XML External Entity (XXE) vulnerability exists in the Amb…7.5
- CVE-2025-23196A code injection vulnerability exists in the Ambari Alert De…8.8
- CVE-2025-23197matrix-hookshot is a Matrix bot for connecting to external s…6.5
Are you affected by CVE-2025-23191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
