SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap businessobjects Business Intelligence Platform |
|
| Vendors & Products |
Sap
Sap businessobjects Business Intelligence Platform |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability. | |
| Title | Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-12-09T02:15:28.146Z
Updated: 2025-12-09T15:58:44.903Z
Reserved: 2025-04-16T13:25:22.788Z
Link: CVE-2025-42896
Updated: 2025-12-09T15:58:41.591Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:52.787
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-42896
No data.