CVE-2026-58248
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP BusinessObjects Business Intelligence | ENTERPRISE 430 | affected |
| SAP_SE | SAP BusinessObjects Business Intelligence | 2025 | affected |
| SAP_SE | SAP BusinessObjects Business Intelligence | 2027 | affected |
| SAP_SE | SAP BusinessObjects Business Intelligence | ENTERPRISECLIENTTOOLS 430 | affected |
Weaknesses
- CWE-611: CWE-611: Improper Restriction of XML External Entity Reference
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.