Junglewise Threat Intelligence

CVE-2026-44743: SAP BusinessObjects sensitive information disclosure in specific endpoint

CVE-2026-44743 · Severity: low · CVSS 3.7 · Published 2026-06-09

Technologies: SAP BusinessObjects Business Intelligence Platform. Vendors: SAP.

Executive brief

SAP BusinessObjects, a suite of reporting and analytics tools, contains a vulnerability that could allow an unauthorized person to view sensitive system information. By accessing a specific web address, an attacker could gain insights into the system's internal configuration. While this does not allow the attacker to change data or shut down the service, it could provide information useful for planning more complex future attacks.

Technical details

An information disclosure vulnerability exists in SAP BusinessObjects (CWE-497) due to the exposure of sensitive system information through a specific endpoint. An unauthenticated attacker can exploit this over the network, though the attack complexity is rated as high, suggesting specific environmental conditions or timing must be met. Successful exploitation results in a low impact on confidentiality, allowing the attacker to read sensitive data that should be restricted. There is no impact on system integrity or availability. SAP has addressed this in their June 2026 Security Patch Day.

Affected products

  • SAP BusinessObjects Business Intelligence platform

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats