medium2026-06-09SAP BusinessObjectsCVE-2026-44755
Email Spoofing in SAP BusinessObjects BI Platform
SAP BusinessObjects BI Platform
Our Take
BusinessObjects has appeared in the last several months of patch cycles. If your BO environment sends automated reports and alerts, email spoofing is a real phishing vector. BO users are often finance and executive stakeholders — high-value targets. Next planned window.
Vulnerability Detail
An email spoofing vulnerability in the SAP BusinessObjects BI Platform allows an attacker to send email notifications that appear to originate from the BI platform but contain attacker-controlled content, potentially used for phishing or social engineering attacks against BI users.
Patch Action
Apply SAP Note 3687096. Verify affected versions in the official SAP Note.
Patch Info