CVE-2024-25646: SAP Businessobjects Web Intelligence
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Affected products
- SAP Businessobjects Web Intelligence: version 420 only; version 430 only; version 440 only
Published 2024-04-09. Last modified 2026-06-17.