CVE-2026-24323: Multiple vulnerabilities in BSP Applications of SAP Document Management System
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24323?
CVE-2026-24323 has been classified with a high severity level due to the potential for unauthenticated remote code execution.
How do I fix CVE-2026-24323?
To fix CVE-2026-24323, it is recommended to apply the latest security patches and updates provided by SAP for affected versions.
What are the affected software versions for CVE-2026-24323?
CVE-2026-24323 affects multiple versions of SAP Document Management System, SAP ERP, and SAP S4CORE including versions 600 to 618 and 102 to 108.
What type of vulnerability is CVE-2026-24323?
CVE-2026-24323 is an injection vulnerability that allows an attacker to execute arbitrary scripts through insufficiently sanitized URL parameters.
Who is vulnerable to CVE-2026-24323?
Any organization using the specified versions of SAP Document Management System, SAP ERP, or SAP S4CORE without applying necessary security updates is vulnerable to CVE-2026-24323.