Cross-Site Request Forgery Vulnerability in SAP Learning Solution by SAP
CVE-2025-31328
What is CVE-2025-31328?
SAP Learning Solution is susceptible to a Cross-Site Request Forgery (CSRF) attack, where an attacker could exploit the vulnerability to deceive authenticated users into unintentionally issuing requests to the server. This situation arises from the naming convention of a GET-based OData function that does not align with its expected behavior. Such an exploit may compromise both the confidentiality and integrity of user data, while the system's availability remains unaffected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP S/4 HANA (Learning Solution) S4HCMGXX 100
SAP S/4 HANA (Learning Solution) 101
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved