Advisory
On 12.08.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP UI5.
SAP Note 3624943 addresses "[CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)" to prevent reverse tabnabbing with a low risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Reverse tabnabbing is an attack where a page linked from the target page is able to rewrite that page, for example
to replace it with a phishing site. The following figure shows a brief illustration:

While the user was originally on the correct page there is a high risk they will not notice that it has been changed to a phishing site.
Risk specification
This note has been re-released with updated solution information. SAP Fiori Launchpad lacks sufficient external navigation protection in tile links, allowing administrators to configure malicious URLs that can hijack user sessions or expose sensitive data.Solution
Fiori Launchpad links now include proper protection annotations for external navigation.