CyberRota Analysis
AI-GeneratedThe @sap/cds-mtxs NPM library is vulnerable due to inadequate checks in its multitenant capabilities, allowing unauthenticated attackers to send crafted requests that can expose sensitive credentials. This could lead to unauthorized modifications or deletions of tenant data, significantly impacting the application's availability and integrity, while also posing a risk to the confidentiality of business data. Organizations utilizing this library, particularly those with multitenant CAP applications and extensibility enabled, should prioritize immediate remediation efforts.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.