CVE-2026-0514

D

ue to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability.

References
Link Resource
https://me.sap.com/notes/3666061 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:*

History

16 Jan 2026, 16:53

Type Values Removed Values Added
First Time Sap
Sap business Connector
CPE cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:*
References () https://me.sap.com/notes/3666061 - () https://me.sap.com/notes/3666061 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory

13 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 02:15

Updated : 2026-01-16 16:53


NVD link : CVE-2026-0514

Mitre link : CVE-2026-0514

CVE.ORG link : CVE-2026-0514


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')