CVE-2026-0514

Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability.
References
Link Resource
https://me.sap.com/notes/3666061 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 02:15

Updated : 2026-01-16 16:53


NVD link : CVE-2026-0514

Mitre link : CVE-2026-0514

CVE.ORG link : CVE-2026-0514


JSON object : View

Products Affected

sap

  • business_connector
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')