Report: Complete Guide to CVE-2026-40137 - Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (T...

Report: Complete Guide to CVE-2026-40137 - Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (T...

CVE ID :CVE-2026-40137 Published : May 12, 2026, 2:23 a.m. | 41 minutes ago Description :SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
May 12, 2026