CVE-2025-42896

MEDIUM

SAP BusinessObjects - SSRF

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (3)
SAP_SE/SAP BusinessObjects Business Intelligence Platform 2025
SAP_SE/SAP BusinessObjects Business Intelligence Platform 2027
SAP_SE/SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430
Published Dec 09, 2025
Tracked Since Feb 18, 2026