CVE-2026-40137

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Configurations

No configuration.

History

12 May 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 03:16

Updated : 2026-06-17 10:44


NVD link : CVE-2026-40137

Mitre link : CVE-2026-40137

CVE.ORG link : CVE-2026-40137


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')