CVE-2025-24868

The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system.
Configurations

No configuration.

History

11 Feb 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 01:15

Updated : 2025-02-11 01:15


NVD link : CVE-2025-24868

Mitre link : CVE-2025-24868

CVE.ORG link : CVE-2025-24868


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')