CVE-2025-42896

MEDIUM

SAP BusinessObjects BI Platform - Login Error URL Server-Side Request Forgery

Title source: manual
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

References (2)

Core 2
Core References

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (3)
SAP_SE/SAP BusinessObjects Business Intelligence Platform 2025
SAP_SE/SAP BusinessObjects Business Intelligence Platform 2027
SAP_SE/SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430
Published Dec 09, 2025
Tracked Since Feb 18, 2026