← Back to CVE List

CVE-2025-24868

Published: 2025-02-11T01:15Z
Last Modified: 2025-02-11T01:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt