SAP Business Connector Open Redirect Vulnerability Allowing Phishing and Unauthorized Actions

Vulnerability

An open redirect vulnerability has been identified in SAP Business Connector. This issue allows an unauthenticated attacker to create a malicious URL that, when accessed by a victim, redirects them to an attacker-controlled site within an embedded frame. Exploitation of this vulnerability could enable the attacker to steal sensitive information and perform unauthorized actions, thereby compromising the confidentiality and integrity of web client data. However, this vulnerability does not affect system availability.

Impact

Exploitation of this vulnerability could lead to phishing attacks, allowing attackers to steal sensitive information from victims. Additionally, it could enable unauthorized actions on behalf of the victim, further compromising web client data.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, particularly on SAP Security Patch Days, which occur on the second Tuesday of each month.

Added: Nov 11, 2025, 1:24 AM
Updated: Nov 11, 2025, 1:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
6.4
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.