SAP BusinessObjects Business Intelligence Platform Session Hijacking Vulnerability

Vulnerability

An information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to hijack sessions over the network without user interaction. This vulnerability enables the attacker to access and modify all application data.

Impact

Exploitation of this vulnerability could lead to unauthorized access and modification of application data, allowing for session hijacking.

Remediation

Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day Bulletin. For guidance on accessing and applying SAP Security Notes, refer to the SAP Security Notes FAQs.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.