medium2026-08-11SAP BusinessObjectsCVE-2026-58248
XML External Entity Injection in SAP BusinessObjects Web Intelligence
SAP BusinessObjects Web Intelligence
Our Take
XXE in Web Intelligence is a known attack class against reporting platforms — crafted report documents are a phishing vector for BI users. Bundle with Note 3756565 (CMS credentials disclosure) in a single BO maintenance window.
Vulnerability Detail
XML External Entity (XXE) injection vulnerability in SAP BusinessObjects Web Intelligence allows an authenticated attacker to submit a crafted XML document that causes the server to process external entity references, potentially leading to server-side request forgery, file disclosure, or denial of service.
Patch Action
Apply SAP Note 3753141. Verify affected versions in the official SAP Note.
Patch Info