MEDIUM
Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
Published Feb 10, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.18%
Description
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Affected products
-
- Version 2008_1_710StatusaffectedConstraints-
- Version 740StatusaffectedConstraints-
- Version 758StatusaffectedConstraints-
- Version ST-PI 2008_1_700StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | Business Server Pages Application (TAF APPLAUNCHER) | unaffected |
|
OR
- 740
- 758
- 2008_1_700
- 2008_1_710
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6874 Advisory
- https://me.sap.com/notes/3688319 Permissions Required
- https://url.sap/sapsecuritypatchday Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6874 | Advisory | |
| https://me.sap.com/notes/3688319 | Permissions Required | |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Feb 10, 2026
Updated Feb 10, 2026
Reserved Jan 21, 2026
Link CVE-2026-24328
CISA Vulnrichment
Updated Feb 10, 2026
ENISA EUVD
EUVD-2026-6874 Assigner sap
Published Feb 10, 2026
Updated Feb 10, 2026
Exploited since n/a
Link EUVD-2026-6874