Impact
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low‑privileged attacker to upload a specially crafted spreadsheet that contains malicious XML External Entity references. When the file is processed, the component resolves the external entities and exposes the contents of sensitive server‑side files in the resulting report. This results in a high impact on confidentiality, with no effect on integrity or availability, and is classified as CWE‑611.
Affected Systems
Affected vendor is SAP, product SAP BusinessObjects Business Intelligence Platform (Web Intelligence). No specific affected version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Because the exploit requires only low‑privileged upload access, the risk to systems with wide upload permissions is significant. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can achieve confidential data exposure by uploading a malicious file through the web interface, making the exploit feasible under typical user privileges.
OpenCVE Enrichment