CVE-2026-24328
Undergoing Analysis Undergoing Analysis - In Progress

Open Redirect in SAP TAF_APPLAUNCHER Enables Phishing Attacks

Vulnerability report for CVE-2026-24328, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-10

Last updated on: 2026-02-17

Assigner: SAP SE

Description

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victimοΏ½s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-10
Last Modified
2026-02-17
Generated
2026-07-26
AI Q&A
2026-02-10
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
sap business_server_pages 2008_1_700
sap business_server_pages 2008_1_710
sap business_server_pages 740
sap business_server_pages 758

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability exists in SAP TAF_APPLAUNCHER within Business Server Pages, where an unauthenticated attacker can create malicious links. When a victim clicks on these links, they are redirected to attacker-controlled sites. This can lead to exposure or alteration of sensitive information within the victim's browser.

Detection Guidance

I don't know

Impact Analysis

This vulnerability can impact you by exposing or altering sensitive information in your browser when you click on a crafted malicious link. The impact on confidentiality and integrity is considered low, and there is no impact on the availability of the application.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24328. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart