← Back

CVE-2026-0505

nvd nist
Published: Feb 10, 2026Modified: Feb 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: CNA

Description

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

Affected (15)

3 products
Document Management System
Erp
S4core
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 602
Version 603
Version 604
Version 605
Version 606
Version 617
Version 618
Sap
Version 102
Version 103
Version 104
Version 105
Version 106
Version 107
Version 108

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.