VDB
CVE-2026-0508
CVE-2026-0508
PUBLISHED
CVSS 7.300000190734863 HIGH
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently download the malicious content. This vulnerability has a high impact on the confidentiality and integrity of the application, with no effect on the availability of the application.
EPSS 0.01% · 2.4th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.01%
2.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sap | businessobjects_business_intelligence_platform | 430, 2027, 2025 |
| SAP_SE | SAP BusinessObjects Business Intelligence Platform | 2025, 2027, * |
Exploit Intelligence
Timeline
- Feb 10, 2026 CVE Published
- Feb 10, 2026 EPSS Score
- Feb 12, 2026 EPSS Score
- Feb 14, 2026 EPSS Score
- Feb 15, 2026 CVE Updated
- Feb 16, 2026 EPSS Score
- Feb 18, 2026 EPSS Score
- Feb 20, 2026 EPSS Score
- Feb 22, 2026 EPSS Score
- Feb 24, 2026 EPSS Score
- Feb 26, 2026 EPSS Score
- Feb 28, 2026 EPSS Score