CVE-2026-24323

MEDIUM EPSS 10.8%
Published Feb 10, 20264mo ago · Modified Jun 17, 20261w ago
6.1 CVSS 3.1
Medium
Find Similar
Published Feb 10, 2026 4mo ago
Last Modified Jun 17, 2026 1w ago

Description

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

CVSS Details

Base Score
6.1
Exploitability
2.8
Impact
2.7
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
10.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-601

Affected Products 15

VendorProductVersionRange
sapdocument_management_system600any
sapdocument_management_system602any
sapdocument_management_system603any
sapdocument_management_system604any
sapdocument_management_system605any
sapdocument_management_system606any
sapdocument_management_system617any
saperp618any
saps4core102any
saps4core103any
saps4core104any
saps4core105any
saps4core106any
saps4core107any
saps4core108any

References 2

  • me.sap.com https://me.sap.com/notes/3678417
    Permissions Required
  • url.sap https://url.sap/sapsecuritypatchday
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.