Advisory
A note with CVSS 7.1 for component BC-XS-SEC was released by SAP on 11.02.2025. The correction/advisory 3563929 was described with "[CVE-2025-24868] Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services)" and affects the system type SAP HANA Platform.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is url redirection vulnerability within SAP HANA Platform.
Risk specification
The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model), allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site due to insufficient validation of redirect URLs, leading to a limited impact on the system's confidentiality, integrity, and availability.Solution
Redirect URL validation has been implemented in UAA for SAP HANA XS advanced model.
- 6.1 Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)
- 6.1 [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP – Business Server Pages Test Application IT00
- 6.1 [CVE-2023-23853] URL Redirection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
- 6.1 [CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)
- 4.3 [CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management