CVE-2024-25646

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_web_intelligence:440:*:*:*:*:*:*:*

History

29 Oct 2025, 14:08

Type Values Removed Values Added
First Time Sap businessobjects Web Intelligence
Sap
References () https://me.sap.com/notes/3421384 - () https://me.sap.com/notes/3421384 - Permissions Required
References () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - Patch
CPE cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_web_intelligence:440:*:*:*:*:*:*:*

Information

Published : 2024-04-09 01:15

Updated : 2025-10-29 14:08


NVD link : CVE-2024-25646

Mitre link : CVE-2024-25646

CVE.ORG link : CVE-2024-25646


JSON object : View

Products Affected

sap

  • businessobjects_web_intelligence
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource