CVE-2025-42893

MEDIUM

SAP Business Connector - Unauthenticated Open Redirect via Malicious URL

Title source: llm
STIX 2.1

Description

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and perform unauthorized actions, impacting the confidentiality and integrity of web client data. There is no impact to system availability resulting from this vulnerability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3662000

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
sap/business_connector 4.8
Published Nov 11, 2025
Tracked Since Feb 18, 2026