CVE-2018-2445: SAP Businessobjects Business Intelligence

Critical severity, CVSS 9.6. EPSS: 1.1% chance of exploitation in the next 30 days.

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

Affected products

  • SAP Businessobjects Business Intelligence: version 4.1 only; version 4.2 only

Published 2018-08-14. Last modified 2026-06-17.