CVE-2026-40137: Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40137?
The severity of CVE-2026-40137 is considered high due to its potential for exploitation through Cross-Site Scripting attacks.
How do I fix CVE-2026-40137?
To fix CVE-2026-40137, it is recommended to update to the latest version of SAP Business Server Pages Application (TAF_APPLAUNCHER) that includes the security patches.
Who is affected by CVE-2026-40137?
CVE-2026-40137 affects users of the SAP Business Server Pages Application (TAF_APPLAUNCHER) who do not have the latest security updates.
Can CVE-2026-40137 lead to data theft?
Yes, CVE-2026-40137 can lead to data theft as the vulnerability allows an attacker to redirect victims to malicious sites.
Is authentication required to exploit CVE-2026-40137?
No, CVE-2026-40137 can be exploited by unauthenticated attackers, making it particularly dangerous.