CVE-2026-24324 PUBLISHED

Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)

Assigner: sap
Reserved: 21.01.2026 Published: 10.02.2026 Updated: 10.02.2026

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor SAP_SE
Product SAP BusinessObjects Business Intelligence Platform (AdminTools)
Versions Default: unaffected
  • Version ENTERPRISE 430 is affected
  • Version 2025 is affected
  • Version 2027 is affected

References

Problem Types