medium2026-08-11SAP BusinessObjectsCVE-2026-58248

XML External Entity Injection in SAP BusinessObjects Web Intelligence

SAP BusinessObjects Web Intelligence

Our Take

XXE in Web Intelligence is a known attack class against reporting platforms — crafted report documents are a phishing vector for BI users. Bundle with Note 3756565 (CMS credentials disclosure) in a single BO maintenance window.

Vulnerability Detail

XML External Entity (XXE) injection vulnerability in SAP BusinessObjects Web Intelligence allows an authenticated attacker to submit a crafted XML document that causes the server to process external entity references, potentially leading to server-side request forgery, file disclosure, or denial of service.

Patch Action

Apply SAP Note 3753141. Verify affected versions in the official SAP Note.

Patch Info

CVSS Score

6.5

SAP Note

3753141

CVE

CVE-2026-58248

Published

2026-08-11

← All patches