CVE-2026-24324 PUBLISHED CVSS 6.5 MEDIUM

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.

EPSS 0.02% · 4.3th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.02%
4.3th percentile

Affected Products

VendorProductVersions
sapbusinessobjects_business_intelligence_platform430, 2025, 2027
SAP_SESAP BusinessObjects Business Intelligence Platform (AdminTools)ENTERPRISE 430, 2025, 2027

Timeline

References

Open in Interactive Console →