RedLine Stealer – Active IOCs
July 14, 2025ICS: Multiple Rockwell Automation Arena Simulation Vulnerabilities
July 14, 2025RedLine Stealer – Active IOCs
July 14, 2025ICS: Multiple Rockwell Automation Arena Simulation Vulnerabilities
July 14, 2025Severity
Medium
Analysis Summary
CVE-2025-42981 CVSS:6.1
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled by the attacker. This allows the attacker to access and/or modify restricted information related to the web client. While the vulnerability poses no impact on data availability, it presents a considerable risk to confidentiality and integrity.
CVE-2025-42979 CVSS:5.6
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this users windows registry could recreate the original password. There is no impact on integrity or availability of the application
CVE-2025-42978 CVSS:3.5
The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being established to a possibly malicious remote TLS server and hence disclose information. Integrity and Availability are not impacted.
CVE-2025-42974 CVSS:4.3
Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is no impact on integrity or availability.
CVE-2025-42973 CVSS:5.4
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected.
Impact
- Gain Access
- Information Disclosure
- Cross-Site Scripting
Indicators of Compromise
CVE
CVE-2025-42981
CVE-2025-42979
CVE-2025-42978
CVE-2025-42974
CVE-2025-42973
Affected Vendors
Affected Products
- SAP Netweaver Application Server
- SAP NetWeaver Application Server Java
- SAP Gui For Windows
- SAP Data Services Management Console
Remediation
Refer to SAP Website for patch, upgrade, or suggested workaround information.