CVE-2025-42981
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2025-42981 is an open redirect vulnerability (CWE-601) in SAP NetWeaver Application Server ABAP that allows unauthenticated attackers to craft malicious URLs embedding scripts that execute in a victim's browser and redirect them to attacker-controlled sites. The vulnerability was published on July 8, 2025, and affects SAP_BASIS versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 816. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ENISA EUVD).

Technical details

The root cause is insufficient sanitization of redirect URL parameters in SAP NetWeaver AS ABAP, classified as CWE-601 (URL Redirection to Untrusted Site). An unauthenticated attacker crafts a URL that embeds a malicious script at an unsanitized location; when a victim clicks the link, the script executes in their browser context and redirects them to an attacker-controlled site. Exploitation requires user interaction (victim clicking the crafted link) but no authentication or special privileges on the part of the attacker. The vulnerability is detectable via Nessus plugin ID 242117 (Feedly, SAP Security Notes).

Impact

Successful exploitation allows an attacker to access and/or modify restricted information related to the web client, presenting a considerable risk to confidentiality and integrity. Because the malicious script executes within the victim's browser session, the attacker may be able to steal session tokens, credentials, or other sensitive data accessible to the web client. Availability is not impacted by this vulnerability (ENISA EUVD, Onapsis).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible SAP NetWeaver AS ABAP instances running affected SAP_BASIS versions (700–816) using tools like Shodan or Censys, or by targeting known SAP web endpoints.
  2. Craft malicious URL: Construct a URL pointing to the vulnerable SAP NetWeaver AS ABAP instance that includes an unsanitized redirect parameter embedding a malicious script or pointing to an attacker-controlled domain (e.g., https://target-sap-server/path?redirect=https://attacker.com/malicious).
  3. Deliver the link: Send the crafted URL to a target victim via phishing email, instant message, or other social engineering channel, impersonating a legitimate SAP notification or business communication.
  4. Script execution and redirect: When the victim clicks the link, the malicious script executes within their browser in the context of the SAP application, and the victim is redirected to the attacker-controlled site.
  5. Harvest data: The attacker collects session tokens, credentials, or other sensitive web client information captured via the malicious site or injected script (ENISA EUVD, Onapsis).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS redirects from SAP NetWeaver AS ABAP to unexpected external domains; unusual referrer headers in web server logs pointing to crafted SAP URLs.
  • Logs: SAP web access logs showing requests with suspicious redirect or URL parameters containing external domains or encoded script content; repeated access to redirect-handling endpoints from varied source IPs.
  • User Reports: End users reporting unexpected redirects to unfamiliar websites after clicking SAP-related links, or browser security warnings triggered by SAP application URLs.

Mitigation and workarounds

SAP addressed CVE-2025-42981 in its July 2025 Patch Day via SAP Security Note 3617131. Organizations should apply the relevant SAP_BASIS patches for all affected versions (700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816) as the primary remediation. As a general workaround, restrict access to SAP NetWeaver AS ABAP web interfaces to trusted networks and educate users to verify URLs before clicking SAP-related links (SAP Security Notes, SAP Note 3617131).

Community reactions

The vulnerability was covered as part of SAP's July 2025 Patch Day roundups by multiple security vendors and researchers. Onapsis, SecurityBridge, and RedRays each published patch day summaries noting CVE-2025-42981 among the 27 flaws addressed in July 2025, with 7 rated critical. GBHackers and CyberSecurityNews also reported on the broader SAP July 2025 patch release. Community reaction was measured, consistent with the Medium severity rating and the social-engineering prerequisite for exploitation (Onapsis, SecurityBridge, GBHackers).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27671CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27680MEDIUM4.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management