CVE-2025-31328: SAP SE SAP s/4 Hana Learning Solution

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

Affected products

  • SAP SE SAP s/4 Hana Learning Solution: version S4HCMGXX 100 only; version 101 only

Published 2025-04-22. Last modified 2026-06-17.