Description
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low‑privileged attacker to upload a specially crafted spreadsheet that contains malicious XML External Entity references. When the file is processed, the component resolves the external entities and exposes the contents of sensitive server‑side files in the resulting report. This results in a high impact on confidentiality, with no effect on integrity or availability, and is classified as CWE‑611.

Affected Systems

Affected vendor is SAP, product SAP BusinessObjects Business Intelligence Platform (Web Intelligence). No specific affected version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. Because the exploit requires only low‑privileged upload access, the risk to systems with wide upload permissions is significant. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can achieve confidential data exposure by uploading a malicious file through the web interface, making the exploit feasible under typical user privileges.

Generated by OpenCVE AI on August 11, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply SAP security patch #3753141, which corrects the XML external entity handling in Web Intelligence.
  • Restrict file‑upload rights to accounts that do not need to edit spreadsheets, minimizing the attack surface.
  • Configure or upgrade the application to disable XML external entity support or enforce strict XML validation to prevent external entity resolution.

Generated by OpenCVE AI on August 11, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Title XML External Entity Injection in SAP BusinessObjects Business Intelligence
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:17:16.740Z

Reserved: 2026-06-29T19:35:04.186Z

Link: CVE-2026-58248

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference