Executive brief
SAP BusinessObjects Business Intelligence Platform's Admin Tools component fails to properly enforce role-based access controls on certain administrative functions. An authenticated but non-privileged user can bypass these restrictions to view sensitive information about platform configuration and administrative features. While the direct impact is limited to confidential information disclosure, this could expose details useful for planning further attacks against the platform.
Technical details
This vulnerability is an authorization bypass in SAP BusinessObjects BI Platform's Admin Tools component, where certain administrative functions lack sufficient access control checks. The vulnerability requires an authenticated, non-administrative user account to exploit; unauthenticated attackers cannot access the affected functionality. An attacker with valid credentials can bypass authorization checks to retrieve limited information about administrative capabilities and platform configuration. The impact is restricted to confidentiality (information disclosure), with no impact on integrity or availability. SAP released patches for this issue as part of its August 11, 2026 security patch day; customers should consult SAP Note 3770649 for affected product versions and patch availability.
Affected products
- SAP BusinessObjects Business Intelligence Platform <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched