CVE-2025-31332 Details
Description
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerability does not disclose any sensitive data.
A vulnerability exists in SAP BusinessObjects Business Intelligence Platform due to insecure file permissions. This issue allows an attacker with local access to the system to modify files, potentially disrupting operations or causing service downtime. While this vulnerability could lead to significant impacts on system integrity and availability, it does not expose any sensitive data.
Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP Security Notes portal in SAP for Me. For more information on SAP Security Patch Days and how to access Security Notes, refer to the SAP Security Notes FAQ.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3565751 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-277 | Insecure Inherited Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap businessobjects business intelligence platform | 430 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Initial Analysis | [email protected] |
| Apr 8, 2025 | New CVE Received | [email protected] |