Impact
The vulnerability is a missing authorization check in SAP BusinessObjects Business Intelligence Platform (Admin Tools). An authenticated non‑administrative user can bypass restrictions and obtain limited information about certain administrative functionality. The resulting confidentiality impact is low and there is no effect on integrity or availability.
Affected Systems
The affected product is SAP BusinessObjects Business Intelligence Platform (Admin Tools) from SAP SE. No specific version range was disclosed, so all current installations of this component may be susceptible until an official fix is released.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as low severity. EPSS data is not available, and it is not listed in CISA KEV. Because the flaw requires authentication, the attack vector is likely remote authenticated, with the attacker needing a user account with limited privileges. The absence of an official patch means the risk remains until a vendor update addresses the issue.
OpenCVE Enrichment