Remote Code Execution Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2025-42896
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42896?
The SAP BusinessObjects Business Intelligence Platform is susceptible to a vulnerability that allows unauthenticated remote attackers to exploit URL parameters associated with the login page. By sending specifically crafted requests, attackers can manipulate the server to fetch unauthorized URLs they supply. This flaw poses a potential risk to data confidentiality and integrity, enabling malicious actors to exploit the system for unauthorized information access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430
SAP BusinessObjects Business Intelligence Platform 2025
SAP BusinessObjects Business Intelligence Platform 2027
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved