CVE Database
/

CVE-2026-24328

Back to search

CVE-2026-24328

Published: Feb 10, 2026

Modified: Feb 10, 2026

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

VendorProductVersions

SAP_SE

Business Server Pages Application (TAF_APPLAUNCHER)

affected
ST-PI 2008_1_700
affected
2008_1_710
affected
740
affected
758

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now