CVE-2026-66763
7.9SAP_SE · SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform uses a hard-coded cryptographic key to store sensitive user credentials, risking unauthorized exposure.
Executive summary
A hard-coded cryptographic key vulnerability in the SAP BusinessObjects Business Intelligence Platform allows authenticated attackers to potentially decrypt sensitive user credentials.
Vulnerability
This is a hard-coded cryptographic key vulnerability (CWE-321) that requires the attacker to have high privileges (authenticated) to access and exploit the key.
Business impact
With a CVSS score of 7.9, this vulnerability poses a severe threat to authentication security. If exploited, an attacker with high privileges could compromise sensitive user credentials, potentially leading to widespread unauthorized access across the business intelligence environment.
Remediation
Immediate Action: Apply the relevant security patches provided by SAP via the official SAP Security Patch Day channels.
Proactive Monitoring: Audit Central Management Server configuration logs for unauthorized access or attempts to extract cryptographic materials.
Compensating Controls: Enforce strict internal access controls to limit the number of users with high-level administrative privileges, thereby reducing the attack surface for this vulnerability.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should prioritize the deployment of the official SAP security updates. Given the sensitivity of credentials handled by the BI platform, securing the cryptographic storage mechanism is vital to maintaining the confidentiality and integrity of the entire business intelligence infrastructure.