Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform
Vulnerability Description
SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-42896
Credits & Attribution
No credits recorded in the NVD database.
More from SAP_SE
View All →Affected Vendor
SAP_SE
View all reports →