CVE-2026-24324: Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24324?
CVE-2026-24324 is classified as a denial of service vulnerability affecting SAP BusinessObjects Business Intelligence Platform (AdminTools).
How do I fix CVE-2026-24324?
To mitigate CVE-2026-24324, update your SAP BusinessObjects Business Intelligence Platform (AdminTools) to the latest available version provided by SAP.
Who is affected by CVE-2026-24324?
Authenticated users with privileges in SAP BusinessObjects Business Intelligence Platform (AdminTools) are affected by CVE-2026-24324.
What type of attack utilizes CVE-2026-24324?
CVE-2026-24324 can be exploited through a denial of service attack by executing a specific query in AdminTools.
What are the consequences of CVE-2026-24324?
The consequences of CVE-2026-24324 include potential downtime and disruption of services in the SAP BusinessObjects Business Intelligence Platform (AdminTools).