CVE-2026-40137 PUBLISHED

Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)

Assigner: sap
Reserved: 09.04.2026 Published: 12.05.2026 Updated: 12.05.2026

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor SAP_SE
Product Business Server Pages Application (TAF_APPLAUNCHER)
Versions Default: unaffected
  • Version ST-PI 740 is affected
  • Version 758 is affected

References

Problem Types