VDB

CVE-2026-0508

CVE-2026-0508 PUBLISHED CVSS 7.300000190734863 HIGH

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently download the malicious content. This vulnerability has a high impact on the confidentiality and integrity of the application, with no effect on the availability of the application.

EPSS 0.01% · 2.4th percentile

Risk Scores

CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.01%
2.4th percentile

Affected Products

VendorProductVersions
sapbusinessobjects_business_intelligence_platform430, 2027, 2025
SAP_SESAP BusinessObjects Business Intelligence Platform2025, 2027, *

Timeline

  • Feb 10, 2026 CVE Published
  • Feb 10, 2026 EPSS Score
  • Feb 12, 2026 EPSS Score
  • Feb 14, 2026 EPSS Score
  • Feb 15, 2026 CVE Updated
  • Feb 16, 2026 EPSS Score
  • Feb 18, 2026 EPSS Score
  • Feb 20, 2026 EPSS Score
  • Feb 22, 2026 EPSS Score
  • Feb 24, 2026 EPSS Score
  • Feb 26, 2026 EPSS Score
  • Feb 28, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›