CVE-2026-24324
Denial of Service via Query Execution in SAP BusinessObjects CMS
Publication date: 2026-02-10
Last updated on: 2026-02-17
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | businessobjects_business_intelligence_platform | 430 |
| sap | businessobjects_business_intelligence_platform | 2025 |
| sap | businessobjects_business_intelligence_platform | 2027 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-405 | The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric." |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP BusinessObjects Business Intelligence Platform (AdminTools). An authenticated attacker who has user privileges can execute a specific query within AdminTools that causes the Content Management Server (CMS) to crash. This crash can make the CMS partially or completely unavailable.
The result is a denial of service condition for the CMS, affecting system availability. However, the vulnerability does not impact the confidentiality or integrity of the system.
How can this vulnerability impact me? :
The primary impact of this vulnerability is on system availability. If exploited, it can cause the Content Management Server (CMS) to crash, leading to partial or complete unavailability of the CMS.
This denial of service can disrupt normal operations that depend on the CMS, potentially causing downtime and affecting business continuity.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability impacts system availability but does not affect confidentiality or integrity of data.
Since regulations like GDPR and HIPAA emphasize the protection of personal data confidentiality and integrity, this vulnerability may have limited direct impact on compliance with those aspects.
However, the denial of service could affect availability requirements under these regulations, potentially impacting compliance if critical services are disrupted.
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
I don't know