6.5
CVE-2026-58248
- EPSS 0.28%
- Veröffentlicht 11.08.2026 00:17:16
- Zuletzt bearbeitet 26.08.2026 19:00:14
- Erkennungen
XML External Entity Injection in SAP BusinessObjects Business Intelligence
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP BusinessObjects Business Intelligence
Default Statusunaffected
Version
ENTERPRISE 430
Status
affected
Version
2025
Status
affected
Version
2027
Status
affected
Version
ENTERPRISECLIENTTOOLS 430
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.204 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| SAP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3753141