Home

Description

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

PUBLISHED Reserved 2026-01-21 | Published 2026-02-10 | Updated 2026-02-10 | Assigner sap




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-601: URL Redirection to Untrusted Site

Product status

Default status
unaffected

SAP_APPL 618
affected

S4CORE 102
affected

103
affected

104
affected

105
affected

106
affected

107
affected

108
affected

109
affected

EA-APPL 600
affected

602
affected

603
affected

604
affected

605
affected

606
affected

617
affected

References

me.sap.com/notes/3678417

url.sap/sapsecuritypatchday

cve.org (CVE-2026-24323)

nvd.nist.gov (CVE-2026-24323)

Download JSON