Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform
CVE-2025-42988

3.7LOW

What is CVE-2025-42988?

The SAP Business Objects Business Intelligence Platform presents a vulnerability that allows unauthenticated attackers to enumerate HTTP endpoints within the internal network. This is achieved by sending specially crafted HTTP requests, potentially leading to information disclosure. While this vulnerability does not compromise the integrity or availability of the application, it may pave the way for more severe attack vectors, such as Server-Side Request Forgery (SSRF). For additional details, you may refer to SAP's support resources.

Affected Version(s)

SAP Business Objects Business Intelligence Platform ENTERPRISE 430

SAP Business Objects Business Intelligence Platform 2025

SAP Business Objects Business Intelligence Platform 2027

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42988 : Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform