Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3666061 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
History
16 Jan 2026, 16:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://me.sap.com/notes/3666061 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Vendor Advisory | |
| CPE | cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:* | |
| First Time |
Sap
Sap business Connector |
13 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 02:15
Updated : 2026-01-16 16:53
NVD link : CVE-2026-0514
Mitre link : CVE-2026-0514
CVE.ORG link : CVE-2026-0514
JSON object : View
Products Affected
sap
- business_connector
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
