CVE-2026-0505: Multiple vulnerabilities in BSP Applications of SAP Document Management System
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0505?
CVE-2026-0505 is classified as a moderate severity vulnerability due to its potential for unauthenticated user exploitation.
How do I fix CVE-2026-0505?
To fix CVE-2026-0505, validate all user-controlled URL parameters within your SAP Document Management System applications to prevent unvalidated redirections.
What types of attacks are possible with CVE-2026-0505?
CVE-2026-0505 could be exploited for unvalidated redirection attacks, leading users to attacker-controlled websites.
Which SAP components are affected by CVE-2026-0505?
CVE-2026-0505 specifically impacts the BSP applications of the SAP Document Management System.
Is authentication required to exploit CVE-2026-0505?
No, exploitation of CVE-2026-0505 does not require user authentication, making it more critical.