PT-2025-32603 · Sap · Sap Fiori
Published
2025-08-12
·
Updated
2025-08-12
·
CVE-2025-42941
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Fiori (Launchpad) (affected versions not specified)
Description:
SAP Fiori (Launchpad) is susceptible to a Reverse Tabnabbing issue stemming from insufficient external navigation protection for its link elements (
<a>). An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. The attacker does not require administrative privileges to execute the attack in certain configurations. This could lead to unintended manipulation of user sessions or exposure of sensitive information. The issue impacts the confidentiality and integrity of the system, but availability remains unaffected.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Fiori