Back

MEDIUM

Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)

Published Feb 10, 2026

Description

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Feb 10, 2026
Updated Feb 10, 2026
Reserved Jan 21, 2026
CISA Vulnrichment
Updated Feb 10, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner sap
Published Feb 10, 2026
Updated Feb 10, 2026
Exploited since n/a
EUVD-2026-6874