PT-2025-24590 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2025-06-10

·

Updated

2025-10-23

·

CVE-2025-42988

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Business Objects Business Intelligence Platform (affected versions not specified)
Description The issue allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by manipulating specific HTTP requests. This information disclosure could enable the attacker to cause Server-Side Request Forgery (SSRF). It does not affect the integrity or availability of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-10427
CVE-2025-42988

Affected Products

Sap Businessobjects Business Intelligence Platform