Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. Confidentiality and availability are not impacted.
History

Tue, 13 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap supplier Relationship Management
Vendors & Products Sap
Sap supplier Relationship Management

Tue, 13 Jan 2026 01:45:00 +0000

Type Values Removed Values Added
Description Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. Confidentiality and availability are not impacted.
Title Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-01-13T14:40:20.471Z

Reserved: 2025-12-09T22:06:51.573Z

Link: CVE-2026-0513

cve-icon Vulnrichment

Updated: 2026-01-13T14:39:51.565Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T02:15:53.957

Modified: 2026-01-13T14:03:18.990

Link: CVE-2026-0513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-13T09:27:03Z