CSRF Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2026-0502

5.4MEDIUM

What is CVE-2026-0502?

An insufficient Cross-Site Request Forgery (CSRF) protection mechanism in the SAP BusinessObjects Business Intelligence Platform allows authenticated users to be deceived by an attacker, leading to unintended requests sent to the web server. While this vulnerability compromises integrity and availability, data confidentiality remains intact. It emphasizes the need for robust CSRF protections in critical web applications.

Affected Version(s)

SAP BusinessObjects Business Intelligence Platform ENTERPRISE 430

SAP BusinessObjects Business Intelligence Platform 2025

SAP BusinessObjects Business Intelligence Platform 2027

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.