Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3666061 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-01-13 02:15
Updated : 2026-01-16 16:53
NVD link : CVE-2026-0514
Mitre link : CVE-2026-0514
CVE.ORG link : CVE-2026-0514
JSON object : View
Products Affected
sap
- business_connector
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
