Open Redirect Vulnerability in SAP Business Connector
CVE-2025-42893

6.1MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 November 2025

What is CVE-2025-42893?

An Open Redirect vulnerability exists in SAP Business Connector, enabling an unauthenticated attacker to construct a malicious URL that can redirect users to an attacker-controlled site. This exploitation method takes advantage of the application's handling of URLs, which, when accessed by unsuspecting victims, leads to a compromised environment presented within an embedded frame. By successfully executing this vulnerability, the attacker can potentially intercept sensitive data and perform unauthorized actions, raising significant concerns regarding the confidentiality and integrity of web client data.

Affected Version(s)

SAP Business Connector SAP BC 4.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.