CVE-2025-42896: SAP SE SAP Businessobjects Business Intelligence Platform

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.

Affected products

  • SAP SE SAP Businessobjects Business Intelligence Platform: version 2025 only; version 2027 only

Published 2025-12-09. Last modified 2026-10-07.