CVE-2026-0485
7.5SAP · BusinessObjects BI Platform
An unauthenticated remote attacker can cause a denial of service in the SAP BusinessObjects BI Platform by sending crafted requests that crash the Content Management Server.
Executive summary
A critical denial of service vulnerability in the SAP BusinessObjects BI Platform allows unauthenticated attackers to crash the Content Management Server and disrupt business operations.
Vulnerability
The vulnerability is an asymmetric resource consumption flaw (CWE-405) in the Content Management Server, which can be triggered by an unauthenticated attacker to force a crash and persistent service disruption.
Business impact
This vulnerability poses a significant risk to organizational productivity by enabling a remote, unauthenticated attacker to render the business intelligence infrastructure unavailable. With a CVSS score of 7.5, the flaw is considered High severity due to the ease of exploitation and the potential for complete service outages, which can severely impact data-driven decision making and reporting workflows.
Remediation
Immediate Action: Review SAP Security Note 3678282 and apply the latest security patches provided by the vendor to address the resource handling issue.
Proactive Monitoring: Monitor Content Management Server logs for repeated, anomalous, or malformed request patterns that could indicate an attempt to trigger a service crash.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block suspicious, non-compliant traffic patterns targeted at the BI Platform's management endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for persistent service disruption and the lack of required authentication, this vulnerability represents a high risk to business continuity. Administrators should prioritize the deployment of the official SAP patch as soon as it is made available through the vendor portal to ensure the stability and availability of the BI environment.