PT-2025-32603 · Sap · Sap Fiori

Published

2025-08-12

·

Updated

2025-08-12

·

CVE-2025-42941

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SAP Fiori (Launchpad) (affected versions not specified)
Description: SAP Fiori (Launchpad) is susceptible to a Reverse Tabnabbing issue stemming from insufficient external navigation protection for its link elements (<a>). An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. The attacker does not require administrative privileges to execute the attack in certain configurations. This could lead to unintended manipulation of user sessions or exposure of sensitive information. The issue impacts the confidentiality and integrity of the system, but availability remains unaffected.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-16189
CVE-2025-42941

Affected Products

Sap Fiori