SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely unavailable. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3678282 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Feb 2026, 16:11
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Sap
Sap businessobjects Business Intelligence Platform |
|
| Summary |
|
|
| CPE | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2027:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:* |
|
| References | () https://me.sap.com/notes/3678282 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Vendor Advisory | |
| CWE | NVD-CWE-noinfo |
10 Feb 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 04:16
Updated : 2026-02-17 16:11
NVD link : CVE-2026-0485
Mitre link : CVE-2026-0485
CVE.ORG link : CVE-2026-0485
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence_platform
CWE
