CVE-2026-24324
MEDIUMSAP BusinessObjects - DoS
Title source: llmDescription
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.
Scores
CVSS v3
6.5
EPSS
0.0001
EPSS Percentile
3.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-405
Status
published
Affected Products (3)
sap/businessobjects_business_intelligence_platform
sap/businessobjects_business_intelligence_platform
sap/businessobjects_business_intelligence_platform
Timeline
Published
Feb 10, 2026
Tracked Since
Feb 18, 2026