Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1493 | Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability. |
Thu, 23 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap businessobjects Business Intelligence Platform |
|
| CPEs | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Sap
Sap businessobjects Business Intelligence Platform |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability. | |
| Title | Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console) | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-02-18T18:07:53.865Z
Reserved: 2024-12-05T21:53:07.644Z
Link: CVE-2025-0064
Updated: 2025-02-11T14:48:06.249Z
Status : Analyzed
Published: 2025-02-11T01:15:09.803
Modified: 2025-10-23T18:41:05.110
Link: CVE-2025-0064
No data.
OpenCVE Enrichment
No data.
EUVD