CVE-2026-0489: SAP SE SAP Business One Job Service
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.
Affected products
- SAP SE SAP Business One Job Service: version B1_ON_HANA 10.0 only
Published 2026-03-10. Last modified 2026-06-17.