High severity7.7NVD Advisory· Published Oct 8, 2024· Updated Jun 17, 2026
CVE-2024-37179
CVE-2024-37179
Description
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5(expand)+ 1 more
- (no CPE)
- (no CPE)range: ENTERPRISE 420
cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_business_intelligence:2025:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3478615nvdPermissions Required
News mentions
0No linked articles in our index yet.