Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-42893

Опубликовано: 11 нояб. 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and perform unauthorized actions, impacting the confidentiality and integrity of web client data. There is no impact to system availability resulting from this vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.0009
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
github
3 месяца назад

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and perform unauthorized actions, impacting the confidentiality and integrity of web client data. There is no impact to system availability resulting from this vulnerability.

CVSS3: 6.1
fstec
3 месяца назад

Уязвимость приложения для автоматизации бизнес-процессов и обработки данных SAP Business Connector (SAP BC), связанная с переадресацией на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на вредоносный веб-сайт

EPSS

Процентиль: 26%
0.0009
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601