CVE-2026-24328 PUBLISHED

Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)

Assigner: sap
Reserved: 21.01.2026 Published: 10.02.2026 Updated: 10.02.2026

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor SAP_SE
Product Business Server Pages Application (TAF_APPLAUNCHER)
Versions Default: unaffected
  • Version ST-PI 2008_1_700 is affected
  • Version 2008_1_710 is affected
  • Version 740 is affected
  • Version 758 is affected

References

Problem Types