CVE-2024-25646

HIGH

SAP BusinessObjects Web Intelligence - Authenticated Information Disclosure via Crafted Document

Title source: llm
STIX 2.1

Description

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.

Scores

CVSS v3 7.7
EPSS 0.0042
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
sap/businessobjects_web_intelligence 420
sap/businessobjects_web_intelligence 430
sap/businessobjects_web_intelligence 440
Published Apr 09, 2024
Tracked Since Feb 18, 2026