SAP BI Platform Vulnerability in LogonToken IP Address Modification
CVE-2025-42907
4.3MEDIUM
What is CVE-2025-42907?
The SAP BI Platform contains a vulnerability that allows attackers to manipulate the IP address within the LogonToken for OpenDoc functionality. When the altered link is accessed, it could send unexpected requests to a different server, which, while having minimal impact on data integrity, poses a potential risk by enabling misleading communications. Users are encouraged to review their configurations and apply the latest security patches to mitigate risks associated with this vulnerability.
Affected Version(s)
SAP BI Platform ENTERPRISE 430
SAP BI Platform 2025
SAP BI Platform 2027