Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-42941— Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)

CVSS 3.5 · Low EPSS 0.04% · P11
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-42941

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
Source: NVD (National Vulnerability Database)
Vulnerability Description
SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is necessary for certain configurations, the attacker does not need the administrative privileges to execute the attack. This could result in unintended manipulation of user sessions or exposure of sensitive information. The issue impacts the confidentiality and integrity of the system, but the availability remains unaffected.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用windows.opener访问指向不可信目标的web链接
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP Fiori 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP Fiori是德国思爱普(SAP)公司的一套为SAP应用程序提供用户体验(UX)的设计系统,它为设计人员和开发人员提供了一套工具和指南,能够快速地开发适用于任何平台的应用,为创建者和用户提供一致、创新的体验。 SAP Fiori (Launchpad)存在安全漏洞,该漏洞源于外部导航保护不足,可能导致反向标签劫持攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SAP_SESAP Fiori (Launchpad) SAP_UI 754 -

II. Public POCs for CVE-2025-42941

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-42941

登录查看更多情报信息。

Same Patch Batch · SAP_SE · 2025-08-12 · 16 CVEs total

CVE-2025-429579.9 CRITICALCode Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
CVE-2025-429509.9 CRITICALCode Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)
CVE-2025-429518.8 HIGHBroken Authorization in SAP Business One (SLD)
CVE-2025-429768.1 HIGHMultiple vulnerabilities in SAP NetWeaver Application Server ABAP (BIC Document)
CVE-2025-429466.9 MEDIUMDirectory Traversal vulnerability in SAP S/4HANA (Bank Communication Management)
CVE-2025-429756.1 MEDIUMMultiple vulnerabilities in SAP NetWeaver Application Server ABAP (BIC Document)
CVE-2025-429486.1 MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-429456.1 MEDIUMHTML Injection vulnerability in SAP NetWeaver Application Server ABAP
CVE-2025-429426.1 MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP
CVE-2025-429365.4 MEDIUMMissing Authorization check in SAP NetWeaver Application Server for ABAP
CVE-2025-429494.9 MEDIUMMissing Authorization check in ABAP Platform
CVE-2025-429434.5 MEDIUMInformation Disclosure in SAP GUI for Windows
CVE-2025-429344.3 MEDIUMCRLF Injection vulnerability in SAP S/4HANA (Supplier invoice)
CVE-2025-429354.1 MEDIUMInformation Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Intern
CVE-2025-429553.5 LOWMissing authorization check in SAP Cloud Connector

IV. Related Vulnerabilities

V. Comments for CVE-2025-42941

No comments yet


Leave a comment