CVE-2026-0508
SAP · BusinessObjects Business Intelligence Platform
SAP BusinessObjects BI Platform allows high-privileged authenticated attackers to inject malicious URLs, creating risks of phishing or unauthorized redirects.
Executive summary
High-privileged users can inject malicious URLs into the SAP BusinessObjects BI Platform, potentially facilitating phishing attacks or redirecting users to malicious sites.
Vulnerability
This vulnerability allows an authenticated attacker with high privileges to insert malicious URLs within the application. This is likely due to insufficient input validation in fields that display links to other users.
Business impact
With a CVSS score of 7.3 (High), the primary risk is the exploitation of trust. An attacker could redirect other users (including administrators) to a credential-harvesting site or deliver malware. While it requires high privileges to execute, it can be used for lateral movement or to compromise the workstations of other platform users.
Remediation
Immediate Action: Apply the vendor-provided security updates for SAP BusinessObjects immediately.
Proactive Monitoring: Audit application content for the presence of suspicious external URLs or links that do not conform to corporate domains.
Compensating Controls: Use a secure web gateway to block access to known malicious domains and implement browser-based protections to alert users when they are being redirected to external sites.
Exploitation status
Public Exploit Available: false
Analyst recommendation
While this vulnerability requires high privileges, it should not be ignored. Organizations should apply the patch promptly and ensure that administrative access to the BI platform is strictly controlled and monitored to prevent internal abuse.