← Back

CVE-2026-24328

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: CNA (Secondary)

Description

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Affected (4)

1 product
Business Server Pages
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 2008_1_700
Version 2008_1_710
Version 740
Version 758

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.