CVE-2026-58248: XML External Entity Injection in SAP BusinessObjects Business Intelligence
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58248?
The severity of CVE-2026-58248 is medium with a score of 6.5.
What kind of attack does CVE-2026-58248 facilitate?
CVE-2026-58248 facilitates XML External Entity Injection attacks in SAP BusinessObjects Business Intelligence.
How do I fix CVE-2026-58248?
To fix CVE-2026-58248, it is recommended to apply the latest security patches provided by SAP for the affected software.
Can CVE-2026-58248 be exploited remotely?
Yes, CVE-2026-58248 can be exploited remotely due to its nature of allowing low-privileged attackers to upload malicious files.
What are the potential impacts of CVE-2026-58248?
The potential impacts of CVE-2026-58248 include exposure of sensitive data due to the resolution of malicious external references.