Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. Confidentiality and availability are not impacted.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sap:supplier_relationship_management:700:*:*:*:*:*:*:* cpe:2.3:a:sap:supplier_relationship_management:701:*:*:*:*:*:*:* cpe:2.3:a:sap:supplier_relationship_management:702:*:*:*:*:*:*:* cpe:2.3:a:sap:supplier_relationship_management:713:*:*:*:*:*:*:* cpe:2.3:a:sap:supplier_relationship_management:714:*:*:*:*:*:*:* |
Tue, 13 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supplier Relationship Management |
|
| Vendors & Products |
Sap
Sap supplier Relationship Management |
Tue, 13 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. Confidentiality and availability are not impacted. | |
| Title | Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog) | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2026-01-13T01:15:57.635Z
Updated: 2026-01-13T14:40:20.471Z
Reserved: 2025-12-09T22:06:51.573Z
Link: CVE-2026-0513
Updated: 2026-01-13T14:39:51.565Z
Status : Analyzed
Published: 2026-01-13T02:15:53.957
Modified: 2026-01-22T18:48:53.343
Link: CVE-2026-0513
No data.