Description
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Published: 2026-08-11
Score: 7.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SAP BusinessObjects Business Intelligence Platform stores some credentials using a hard‑coded cryptographic key. An attacker with high privileges and local access to the server can retrieve these objects and decrypt the stored credentials. Successful exploitation would expose sensitive authentication data and allow the attacker to modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Affected Systems

The vulnerability exists in the SAP BusinessObjects Business Intelligence Platform Central Management Server. No specific version range is provided in the advisory, so any installation of the platform should be considered potentially affected until a patch is applied.

Risk and Exploitability

The CVSS score of 7.9 indicates high severity. The EPSS score is not available, and the flaw is not listed in CISA KEV. The attack vector is inferred to be local, requiring an attacker to have administrative privileges on the server. Therefore, the exploitation probability may be moderate, but environments that allow local access without strict controls remain at significant risk.

Generated by OpenCVE AI on August 11, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP security patch referenced in SAP Note 3756565.
  • Restrict local access and enforce least privilege for users that can log into the Central Management Server.
  • Replace hard‑coded cryptographic keys with securely stored keys or implement unique key generation per installation to address the key‑management weakness (CWE‑321).

Generated by OpenCVE AI on August 11, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Title Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T00:17:50.193Z

Reserved: 2026-07-27T17:33:40.733Z

Link: CVE-2026-66763

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T01:30:04Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key