CVE-2026-24323 Details
Description
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.
A cross-site scripting (XSS) vulnerability has been identified in SAP BSP applications. This issue allows an unauthenticated user to inject malicious scripts through user-controlled URL parameters that are not properly sanitized. When a victim accesses a manipulated URL, the injected script executes in the victim's browser. This vulnerability has a low impact on confidentiality and integrity, with no effect on the application's availability.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3678417 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap document management system | 600 602 603 604 605 606 617 |
CPE
Remediation
| |
| sap erp | 618 |
CPE
Remediation
| |
| sap s4core | 102 103 104 105 106 107 108 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | [email protected] |