CVE 4.2 MEDIUM

Path Traversal Vulnerability in SAP Fiori (launchpad)_CVE-2026-24315

4.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Description

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

Basic Information

ID CVE-2026-24315
Source sap
Published Jun 9, 2026 at 00:19

Affected Product

Vendor SAP_SE
Product SAP Fiori (launchpad)
Version SAP_UI 754
Affected Versions SAP_SE SAP Fiori (launchpad) SAP_UI 754
SAP_SE SAP Fiori (launchpad) 755
SAP_SE SAP Fiori (launchpad) 756
SAP_SE SAP Fiori (launchpad) 757
SAP_SE SAP Fiori (launchpad) 758
SAP_SE SAP Fiori (launchpad) 816

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.