PT-2025-46233 · Sap · Sap Business Connector

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-42893

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Connector (affected versions not specified)
Description An unauthenticated attacker can exploit an Open Redirect flaw in SAP Business Connector by creating a malicious URL. If a user accesses this URL, they are redirected to a website controlled by the attacker, which is displayed within an embedded frame. Successful exploitation could lead to the theft of sensitive information and the execution of unauthorized actions, compromising the confidentiality and integrity of web client data. System availability is not affected by this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2025-14450
CVE-2025-42893

Affected Products

Sap Business Connector