CVE-2025-24868: Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services)
The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24868?
CVE-2025-24868 is classified as a high-severity vulnerability due to its potential for exploitation by unauthenticated attackers.
How do I fix CVE-2025-24868?
To fix CVE-2025-24868, users should apply the available security patches provided by SAP for the SAP HANA extended application services, advanced model.
Who is affected by CVE-2025-24868?
CVE-2025-24868 affects users of the SAP HANA extended application services, advanced model that have not implemented recommended security configurations.
What type of attack can CVE-2025-24868 facilitate?
CVE-2025-24868 can facilitate phishing attacks by allowing attackers to redirect victims to malicious sites through crafted links.
Is user authentication required to exploit CVE-2025-24868?
No, CVE-2025-24868 can be exploited without user authentication, making it particularly dangerous.