Reverse Tabnabbing Vulnerability in SAP Fiori Launchpad
CVE-2025-42941
What is CVE-2025-42941?
SAP Fiori (Launchpad) suffers from a reverse tabnabbing vulnerability due to insufficient protections against external navigation for its link elements. An attacker could exploit this flaw by leveraging compromised or malicious web pages, potentially resulting in unauthorized manipulation of user sessions or the exposure of confidential information. Although administrative user privileges may facilitate exploit configurations, they are not required to carry out the attack. This vulnerability raises significant concerns regarding the confidentiality and integrity of the SAP Fiori system, although system availability remains untouched.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Fiori (Launchpad) SAP_UI 754
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved