CVE-2025-42988 Details
Description
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable the researcher to cause SSRF. It has no impact on integrity and availability of the application.
A vulnerability in SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints within the internal network by sending specially crafted HTTP requests. This information disclosure could potentially be exploited to cause Server-Side Request Forgery (SSRF). The vulnerability does not impact the application's integrity or availability.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day Bulletin. This vulnerability will be addressed in the upcoming SAP Security Patch Day on January 14, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3585545 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap businessobjects business intelligence platform | 430 2025 2027 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | Initial Analysis | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |