Medium severity6.1NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026
CVE-2026-0505
CVE-2026-0505
Description
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:sap:document_management_system:600:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:document_management_system:600:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:602:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:603:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:604:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:605:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:606:*:*:*:*:*:*:*
- cpe:2.3:a:sap:document_management_system:617:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:104:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:105:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:106:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:107:*:*:*:*:*:*:*
- cpe:2.3:a:sap:s4core:108:*:*:*:*:*:*:*
- SAP_SE/SAP Document Management Systemv5Range: SAP_APPL 618
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3678417nvdPermissions Required
News mentions
0No linked articles in our index yet.