Security Flaw in SAP TAF_APPLAUNCHER Affects Business Server Pages
CVE-2026-40137
6.1MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40137?
The SAP TAF_APPLAUNCHER component within Business Server Pages presents a security vulnerability that enables unauthenticated attackers to create malicious links. When these links are accessed by unsuspecting users, they may be redirected to sites controlled by the attackers. This poses risks to the confidentiality and integrity of sensitive information within the victim's browser, as unauthorized data exposure or alteration can occur without impacting the application's overall availability.
Affected Version(s)
Business Server Pages Application (TAF_APPLAUNCHER) ST-PI 740
Business Server Pages Application (TAF_APPLAUNCHER) 758