CVE-2026-0508
- EPSS 0.28%
- Veröffentlicht 10.02.2026 03:01:41
- Zuletzt bearbeitet 17.02.2026 16:06:15
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unv...
CVE-2026-0490
- EPSS 0.36%
- Veröffentlicht 10.02.2026 03:01:20
- Zuletzt bearbeitet 17.02.2026 16:06:59
SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high...
CVE-2026-0485
- EPSS 0.4%
- Veröffentlicht 10.02.2026 03:00:49
- Zuletzt bearbeitet 17.02.2026 16:11:42
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could...
CVE-2025-42896
- EPSS 0.31%
- Veröffentlicht 09.12.2025 02:15:28
- Zuletzt bearbeitet 07.10.2026 20:10:01
SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resultin...
CVE-2025-42985
- EPSS 0.23%
- Veröffentlicht 08.07.2025 00:38:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client dat...
CVE-2025-42965
- EPSS 0.23%
- Veröffentlicht 08.07.2025 00:36:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer...
CVE-2025-31326
- EPSS 0.23%
- Veröffentlicht 08.07.2025 00:34:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or man...
CVE-2025-42988
- EPSS 0.22%
- Veröffentlicht 10.06.2025 00:12:00
- Zuletzt bearbeitet 23.10.2025 14:26:31
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further ena...
CVE-2025-43000
- EPSS 0.16%
- Veröffentlicht 13.05.2025 00:17:59
- Zuletzt bearbeitet 15.04.2026 00:35:42
Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.
CVE-2025-31332
- EPSS 0.14%
- Veröffentlicht 08.04.2025 07:15:36
- Zuletzt bearbeitet 24.10.2025 18:08:22
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on in...