CVE-2026-24328: SAP Business Server Pages

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Affected products

  • SAP Business Server Pages: version 740 only; version 758 only; version 2008_1_700 only; version 2008_1_710 only

Published 2026-02-10. Last modified 2026-06-17.