CVE-2026-0508

SAP · BusinessObjects Business Intelligence Platform

SAP BusinessObjects BI Platform allows high-privileged authenticated attackers to inject malicious URLs, creating risks of phishing or unauthorized redirects.

Executive summary

High-privileged users can inject malicious URLs into the SAP BusinessObjects BI Platform, potentially facilitating phishing attacks or redirecting users to malicious sites.

Vulnerability

This vulnerability allows an authenticated attacker with high privileges to insert malicious URLs within the application. This is likely due to insufficient input validation in fields that display links to other users.

Business impact

With a CVSS score of 7.3 (High), the primary risk is the exploitation of trust. An attacker could redirect other users (including administrators) to a credential-harvesting site or deliver malware. While it requires high privileges to execute, it can be used for lateral movement or to compromise the workstations of other platform users.

Remediation

Immediate Action: Apply the vendor-provided security updates for SAP BusinessObjects immediately.

Proactive Monitoring: Audit application content for the presence of suspicious external URLs or links that do not conform to corporate domains.

Compensating Controls: Use a secure web gateway to block access to known malicious domains and implement browser-based protections to alert users when they are being redirected to external sites.

Exploitation status

Public Exploit Available: false

Analyst recommendation

While this vulnerability requires high privileges, it should not be ignored. Organizations should apply the patch promptly and ensure that administrative access to the BI platform is strictly controlled and monitored to prevent internal abuse.