PT-2025-49771 · Sap · Sap Businessobjects Business Intelligence Platform

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-42896

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence Platform (affected versions not specified)
Description An unauthenticated remote attacker can send specially crafted requests through a URL parameter controlling the login page error message. This can cause the server to retrieve URLs supplied by the attacker, potentially impacting confidentiality and integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2025-15898
CVE-2025-42896

Affected Products

Sap Businessobjects Business Intelligence Platform