CVE-2025-0061: SAP Businessobjects Business Intelligence Platform
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.
Affected products
- SAP Businessobjects Business Intelligence Platform: version 420 only; version 430 only; version 2025 only
Published 2025-01-14. Last modified 2026-06-17.