CVE-2026-24328

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
References
Link Resource
https://me.sap.com/notes/3688319 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_server_pages:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_server_pages:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_server_pages:2008_1_700:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_server_pages:2008_1_710:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:10


NVD link : CVE-2026-24328

Mitre link : CVE-2026-24328

CVE.ORG link : CVE-2026-24328


JSON object : View

Products Affected

sap

  • business_server_pages
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')