Security Flaw in SAP TAF_APPLAUNCHER Affects Business Server Pages
CVE-2026-40137

6.1MEDIUM

What is CVE-2026-40137?

The SAP TAF_APPLAUNCHER component within Business Server Pages presents a security vulnerability that enables unauthenticated attackers to create malicious links. When these links are accessed by unsuspecting users, they may be redirected to sites controlled by the attackers. This poses risks to the confidentiality and integrity of sensitive information within the victim's browser, as unauthorized data exposure or alteration can occur without impacting the application's overall availability.

Affected Version(s)

Business Server Pages Application (TAF_APPLAUNCHER) ST-PI 740

Business Server Pages Application (TAF_APPLAUNCHER) 758

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.