Executive brief
SAP BusinessObjects Business Intelligence Platform, a suite used for data reporting and analysis, contains a vulnerability that allows authenticated users to spoof emails. An attacker could send fraudulent emails that appear to originate from a legitimate source within the platform. While this does not allow for data theft or system downtime, it can be used to facilitate phishing attacks or damage organizational reputation.
Technical details
An email spoofing vulnerability exists in SAP BusinessObjects Business Intelligence Platform due to insufficient validation of email sending parameters. An authenticated attacker with low privileges can manipulate these parameters to send emails with forged sender identities. The vulnerability is classified as an origin validation error (CWE-346). It has a low impact on integrity and no impact on confidentiality or availability. A fix is available via SAP Security Note 3687096.
Affected products
- SAP BusinessObjects Business Intelligence Platform
Timeline
- 2026-06-09: advisory: Initial disclosure by SAP and NVD.