High severity7.7NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-25646
CVE-2024-25646
Description
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: 420
cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_web_intelligence:440:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- support.sap.com/en/my-support/knowledge-base/security-notes-news.htmlnvdPatch
- me.sap.com/notes/3421384nvdPermissions Required
News mentions
0No linked articles in our index yet.