CVE 6.1 MEDIUM

Multiple vulnerabilities in BSP Applications of SAP Document Management System_CVE-2026-24323

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim๏ฟฝs browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

Basic Information

ID CVE-2026-24323
Source sap
Published Feb 10, 2026 at 03:04

Affected Product

Vendor SAP_SE
Product SAP Document Management System
Version SAP_APPL 618
Affected Versions SAP_SE SAP Document Management System SAP_APPL 618
SAP_SE SAP Document Management System S4CORE 102
SAP_SE SAP Document Management System 103
SAP_SE SAP Document Management System 104
SAP_SE SAP Document Management System 105
SAP_SE SAP Document Management System 106
SAP_SE SAP Document Management System 107
SAP_SE SAP Document Management System 108
SAP_SE SAP Document Management System 109
SAP_SE SAP Document Management System EA-APPL 600
SAP_SE SAP Document Management System 602
SAP_SE SAP Document Management System 603
SAP_SE SAP Document Management System 604
SAP_SE SAP Document Management System 605
SAP_SE SAP Document Management System 606
SAP_SE SAP Document Management System 617

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.