Executive brief
SAP Business Server Pages contains a vulnerability in the TAF_APPLAUNCHER component that allows attackers to create deceptive links. If a user clicks one of these links, they can be redirected to a malicious website controlled by the attacker. This could lead to the theft of sensitive browser-based information or unauthorized changes to data within the user's session.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the SAP TAF_APPLAUNCHER component within Business Server Pages (BSP). The flaw stems from improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by persuading a user to click a specially crafted URL. Successful exploitation allows the attacker to redirect the victim to an arbitrary external domain, potentially enabling the theft of session cookies or the modification of content within the victim's browser context. The vulnerability has a CVSS base score of 6.1, reflecting a requirement for user interaction and a 'Changed' scope.
Affected products
- SAP Business Server Pages (TAF_APPLAUNCHER)
Timeline
- 2026-05-12: advisory: Initial advisory published by SAP and NVD