CVE-2026-0485 PUBLISHED

Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform

Assigner: sap
Reserved: 09.12.2025 Published: 10.02.2026 Updated: 10.02.2026

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely unavailable. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor SAP_SE
Product SAP BusinessObjects BI Platform
Versions Default: unaffected
  • Version ENTERPRISE 430 is affected
  • Version 2025 is affected
  • Version 2027 is affected

References

Problem Types