CVE-2026-0490 PUBLISHED

Denial of service (DOS) in SAP BusinessObjects BI Platform

Assigner: sap
Reserved: 09.12.2025 Published: 10.02.2026 Updated: 10.02.2026

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability but no impact on the confidentiality and integrity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor SAP_SE
Product SAP BusinessObjects BI Platform
Versions Default: unaffected
  • Version ENTERPRISE 430 is affected
  • Version 2025 is affected
  • Version 2027 is affected

References

Problem Types