CVE-2026-0514
Cross-Site Scripting in SAP Business Connector Risks Data Integrity
Publication date: 2026-01-13
Last updated on: 2026-01-13
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | business_connector | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability impacts the confidentiality and integrity of information related to the webclient by allowing an attacker to access or modify such information through a Cross-Site Scripting (XSS) attack. As a result, it could potentially lead to non-compliance with standards and regulations like GDPR and HIPAA, which require protection of personal and sensitive data against unauthorized access and modification.
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Scripting (XSS) issue in SAP Business Connector. An unauthenticated attacker can create a malicious link that, when clicked by a user, redirects them to a site controlled by the attacker. This can lead to unauthorized access or modification of information related to the webclient, affecting confidentiality and integrity.
How can this vulnerability impact me? :
Exploitation of this vulnerability can allow an attacker to access or modify information related to the webclient, impacting the confidentiality and integrity of that information. However, it does not affect the availability of the system.