Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sap:business_connector:4.8:*:*:*:*:*:*:* |
Tue, 13 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap business Connector |
|
| Vendors & Products |
Sap
Sap business Connector |
Tue, 13 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify information related to the webclient, impacting confidentiality and integrity, with no effect on availability. | |
| Title | Cross-Site Scripting (XSS) vulnerability in SAP Business Connector | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-01-13T01:16:03.501Z
Updated: 2026-01-13T14:38:19.675Z
Reserved: 2025-12-09T22:06:52.467Z
Link: CVE-2026-0514
Updated: 2026-01-13T14:38:16.619Z
Status : Analyzed
Published: 2026-01-13T02:15:54.113
Modified: 2026-01-16T16:53:03.113
Link: CVE-2026-0514
No data.