First published: Tue Feb 11 2025(Updated: )
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0064 allows an attacker with admin rights to impersonate any user by generating or retrieving a secret passphrase, posing a significant security risk.
CVE-2025-0064 specifically affects the SAP BusinessObjects Business Intelligence platform.
To fix CVE-2025-0064, update to the latest version of the SAP BusinessObjects Business Intelligence platform that addresses this vulnerability.
CVE-2025-0064 can be exploited under specific conditions where an attacker already possesses admin rights within the Central Management Console.
Yes, SAP has provided patches that address CVE-2025-0064, and it is recommended to apply them as soon as possible.