Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform
CVE-2025-42988
3.7LOW
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-42988?
The SAP Business Objects Business Intelligence Platform presents a vulnerability that allows unauthenticated attackers to enumerate HTTP endpoints within the internal network. This is achieved by sending specially crafted HTTP requests, potentially leading to information disclosure. While this vulnerability does not compromise the integrity or availability of the application, it may pave the way for more severe attack vectors, such as Server-Side Request Forgery (SSRF). For additional details, you may refer to SAP's support resources.
Affected Version(s)
SAP Business Objects Business Intelligence Platform ENTERPRISE 430
SAP Business Objects Business Intelligence Platform 2025
SAP Business Objects Business Intelligence Platform 2027