9.1
CVE-2025-0061
- EPSS 0.51%
- Veröffentlicht 14.01.2025 01:15:16
- Zuletzt bearbeitet 24.10.2025 19:14:21
- Erkennungen
Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Businessobjects Business Intelligence Platform Version 420 SwEdition enterprise
SAP ≫ Businessobjects Business Intelligence Platform Version 430 SwEdition -
SAP ≫ Businessobjects Business Intelligence Platform Version 2025 SwEdition -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.405 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| SAP | 8.7 | 2.2 | 5.8 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3474398