CVE-2025-24868 Information
Feb 12, 2025
cve
Description
The User Account and Authentication service (UAA) for SAP HANA extended application services advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link that when clicked by a victim redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality integrity and availability of the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Reference
https://me.sap.com/notes/3563929 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
7.1
Share on: