← Zuruck zu CVEs
CVE-2025-42893
MEDIUM6.1
Beschreibung
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and perform unauthorized actions, impacting the confidentiality and integrity of web client data. There is no impact to system availability resulting from this vulnerability.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht11/11/2025
Zuletzt geandert1/16/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
sap:business_connector
Schwachen (CWE)
CWE-601
Referenzen
https://me.sap.com/notes/3662000(cna@sap.com)
https://url.sap/sapsecuritypatchday(cna@sap.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.