CVE-2025-42893: Open Redirect vulnerability in SAP Business Connector
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and perform unauthorized actions, impacting the confidentiality and integrity of web client data. There is no impact to system availability resulting from this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42893?
CVE-2025-42893 has a severity classification due to its potential to allow an attacker to redirect users to malicious sites.
How do I fix CVE-2025-42893?
To fix CVE-2025-42893, it is recommended to apply the latest security patches provided by SAP for Business Connector.
Who is affected by CVE-2025-42893?
CVE-2025-42893 affects all versions of SAP Business Connector that are vulnerable to the Open Redirect vulnerability.
What type of attack is facilitated by CVE-2025-42893?
CVE-2025-42893 facilitates Open Redirect attacks, allowing attackers to direct users to malicious sites.
Can CVE-2025-42893 be exploited without authentication?
Yes, CVE-2025-42893 can be exploited by unauthenticated attackers, making it particularly dangerous.