« Volver al listado

CVE-2026-24328

Estado: AnalizadaMedia (6.1)—

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-24328",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-24328",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-10T15:41:38.041599Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "Business Server Pages Application (TAF_APPLAUNCHER)",
          "versions": [
            {
              "status": "affected",
              "version": "ST-PI 2008_1_700"
            },
            {
              "status": "affected",
              "version": "2008_1_710"
            },
            {
              "status": "affected",
              "version": "740"
            },
            {
              "status": "affected",
              "version": "758"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-10T04:16:05.273",
  "references": [
    {
      "url": "https://me.sap.com/notes/3688319",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://url.sap/sapsecuritypatchday",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application."
    },
    {
      "lang": "es",
      "value": "SAP TAF_APPLAUNCHER dentro de Business Server Pages permite a un atacante no autenticado crear enlaces maliciosos que, al ser pulsados por una víctima, los redirigen a sitios controlados por el atacante, exponiendo o alterando potencialmente información sensible en el navegador de la víctima. Esto resulta en un impacto bajo en la confidencialidad y la integridad, sin impacto en la disponibilidad de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T10:22:54.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:business_server_pages:740:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC862E54-CEB7-4A61-BFEC-9ED2372109FC"
            },
            {
              "criteria": "cpe:2.3:a:sap:business_server_pages:758:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41EE398C-9049-44E7-AFCF-26441F66D886"
            },
            {
              "criteria": "cpe:2.3:a:sap:business_server_pages:2008_1_700:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2F28858-4CDD-42CB-93E4-26B56B67B6CE"
            },
            {
              "criteria": "cpe:2.3:a:sap:business_server_pages:2008_1_710:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD8EF5BB-C105-403F-A2C2-F916FE0732E7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}