CVE-2026-24324

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.
References
Link Resource
https://me.sap.com/notes/3695912 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2027:*:*:*:enterprise:*:*:*

History

17 Feb 2026, 15:15

Type Values Removed Values Added
First Time Sap
Sap businessobjects Business Intelligence Platform
Summary
  • (es) SAP BusinessObjects Business Intelligence Platform (AdminTools) permite a un atacante autenticado con privilegios de usuario ejecutar una consulta específica en AdminTools que podría causar la caída del Content Management Server (CMS), dejando el CMS parcial o completamente no disponible y resultando en la denegación de servicio del Content Management Server (CMS). La explotación exitosa afecta la disponibilidad del sistema, mientras que la confidencialidad y la integridad no se ven afectadas.
CPE cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2027:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
CWE NVD-CWE-noinfo
References () https://me.sap.com/notes/3695912 - () https://me.sap.com/notes/3695912 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory

10 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:15


NVD link : CVE-2026-24324

Mitre link : CVE-2026-24324

CVE.ORG link : CVE-2026-24324


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence_platform
CWE
CWE-405

Asymmetric Resource Consumption (Amplification)

NVD-CWE-noinfo