CVE-2024-25646

HIGH

SAP Businessobjects Web Intelligence - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.

Scores

CVSS v3 7.7
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
sap/businessobjects_web_intelligence 420
sap/businessobjects_web_intelligence 430
sap/businessobjects_web_intelligence 440
Published Apr 09, 2024
Tracked Since Feb 18, 2026