Advisory
A note with CVSS 0.0 for component BC-CP-CF-CRTM was released by SAP on 11.03.2025. The correction/advisory 3576540 was described with "Open Source Security Advisory: Best Practices for Securing Spring Boot Actuator Endpoints for applications running on BTP" and affects the system type BTP.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as project.
The vulnerability addressed is missing security configuration within BTP.
Risk specification
Java applications implemented with the Spring Framework are typically running on BTP Cloud Foundry and KYMA environments, in some cases also on the NEO environment. Spring Boot Actuator allows an unauthenticated attacker to access improperly secured endpoints, resulting in unauthorized access to sensitive application data like environment variables and memory dumps.Solution
Spring Boot Actuator needs to be reconfigured or removed to make sure applications are not vulnerable.