CVE-2025-0064

high

Description

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.

References

https://www.securityweek.com/sap-releases-21-security-patches/

https://url.sap/sapsecuritypatchday

https://me.sap.com/notes/3525794

Details

Source: Mitre, NVD

Published: 2025-02-11

Updated: 2025-02-11

Risk Information

CVSS v2

Base Score: 7.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Severity: High