Impact
SAP BusinessObjects Business Intelligence Platform stores some credentials using a hard‑coded cryptographic key. An attacker with high privileges and local access to the server can retrieve these objects and decrypt the stored credentials. Successful exploitation would expose sensitive authentication data and allow the attacker to modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Affected Systems
The vulnerability exists in the SAP BusinessObjects Business Intelligence Platform Central Management Server. No specific version range is provided in the advisory, so any installation of the platform should be considered potentially affected until a patch is applied.
Risk and Exploitability
The CVSS score of 7.9 indicates high severity. The EPSS score is not available, and the flaw is not listed in CISA KEV. The attack vector is inferred to be local, requiring an attacker to have administrative privileges on the server. Therefore, the exploitation probability may be moderate, but environments that allow local access without strict controls remain at significant risk.
OpenCVE Enrichment