CVE-2025-42896: Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity, and no impact to availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42896?
CVE-2025-42896 has a low impact severity level regarding confidentiality.
How do I fix CVE-2025-42896?
To mitigate CVE-2025-42896, it is recommended to apply security patches provided by SAP.
What software is affected by CVE-2025-42896?
CVE-2025-42896 affects the SAP BusinessObjects Business Intelligence Platform.
Can CVE-2025-42896 be exploited remotely?
Yes, CVE-2025-42896 can be exploited by an unauthenticated remote attacker.
What type of attack is associated with CVE-2025-42896?
CVE-2025-42896 allows attackers to send crafted requests that can cause the server to fetch attacker-supplied URLs.