SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on availability.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap e-recruiting Sap s4hana |
|
| Vendors & Products |
Sap
Sap e-recruiting Sap s4hana |
Tue, 11 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on availability. | |
| Title | Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP) | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-11-11T00:20:31.304Z
Updated: 2025-11-12T20:09:38.058Z
Reserved: 2025-04-16T13:25:32.384Z
Link: CVE-2025-42924
Updated: 2025-11-12T17:30:57.548Z
Status : Awaiting Analysis
Published: 2025-11-11T01:15:39.100
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-42924
No data.