CVE-2025-42924: SAP SE SAP s/4hana Landscape SAP E-Recruiting Bsp

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on availability.

Affected products

  • SAP SE SAP s/4hana Landscape SAP E-Recruiting Bsp: version S4ERECRT 100 only; version 200 only; version 603 only; version 604 only; version 605 only; version 606 only; …

Published 2025-11-11. Last modified 2026-06-17.