
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-42981 is an open redirect vulnerability (CWE-601) in SAP NetWeaver Application Server ABAP that allows unauthenticated attackers to craft malicious URLs embedding scripts that execute in a victim's browser and redirect them to attacker-controlled sites. The vulnerability was published on July 8, 2025, and affects SAP_BASIS versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 816. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ENISA EUVD).
The root cause is insufficient sanitization of redirect URL parameters in SAP NetWeaver AS ABAP, classified as CWE-601 (URL Redirection to Untrusted Site). An unauthenticated attacker crafts a URL that embeds a malicious script at an unsanitized location; when a victim clicks the link, the script executes in their browser context and redirects them to an attacker-controlled site. Exploitation requires user interaction (victim clicking the crafted link) but no authentication or special privileges on the part of the attacker. The vulnerability is detectable via Nessus plugin ID 242117 (Feedly, SAP Security Notes).
Successful exploitation allows an attacker to access and/or modify restricted information related to the web client, presenting a considerable risk to confidentiality and integrity. Because the malicious script executes within the victim's browser session, the attacker may be able to steal session tokens, credentials, or other sensitive data accessible to the web client. Availability is not impacted by this vulnerability (ENISA EUVD, Onapsis).
https://target-sap-server/path?redirect=https://attacker.com/malicious).SAP addressed CVE-2025-42981 in its July 2025 Patch Day via SAP Security Note 3617131. Organizations should apply the relevant SAP_BASIS patches for all affected versions (700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816) as the primary remediation. As a general workaround, restrict access to SAP NetWeaver AS ABAP web interfaces to trusted networks and educate users to verify URLs before clicking SAP-related links (SAP Security Notes, SAP Note 3617131).
The vulnerability was covered as part of SAP's July 2025 Patch Day roundups by multiple security vendors and researchers. Onapsis, SecurityBridge, and RedRays each published patch day summaries noting CVE-2025-42981 among the 27 flaws addressed in July 2025, with 7 rated critical. GBHackers and CyberSecurityNews also reported on the broader SAP July 2025 patch release. Community reaction was measured, consistent with the Medium severity rating and the social-engineering prerequisite for exploitation (Onapsis, SecurityBridge, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."