Sceawere
Vulnerability Detail
CVE-2026-58248UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP Web Intelligence External Reference Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP BusinessObjects Business Intelligence
- Attack Type
- CWE-611: Improper Restriction of XML External Entity Reference
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-11T01:17:22.633Z",
"pubdate": "2026-08-11T01:17:22.633Z",
"executiveSummary": "An arbitrary file disclosure vulnerability exists within the SAP BusinessObjects Business Intelligence Platform, specifically affecting the Web Intelligence component. The vulnerability arises from insecure processing of spreadsheet data sources containing malicious external references, allowing an authenticated, low-privileged attacker to compromise confidentiality by reading sensitive server-side files. The successful exploitation of this flaw results in a high impact on the confidentiality of the underlying system, while integrity and availability remain unaffected. The attack requires the ability to upload a specially crafted spreadsheet file and have it processed by the vulnerable component as a data source. This security deficiency poses significant risk regarding unauthorized information disclosure, potentially exposing critical configuration files, system data, or operational secrets accessible to the application context. Mitigation requires applying vendor-supplied patches or updates as they become available and restricting spreadsheet data source processing capabilities.",
"technicalDetails": "The vulnerability resides within the SAP BusinessObjects Business Intelligence Platform (Web Intelligence) data source processing engine. The root cause is the inadequate validation and insecure resolution of external references embedded within imported spreadsheet files. When a low-privileged user uploads a maliciously crafted spreadsheet file and initiates a data source processing workflow, the affected Web Intelligence component automatically attempts to resolve all internal and external references contained within the file structure. During the reference resolution phase, the application fails to restrict file access boundaries, allowing the parser to interpret external references pointing to local server-side files. The payload behavior involves structuring the spreadsheet references to target sensitive system files or application configuration paths. As the Web Intelligence component processes the file, it reads the targeted server-side file contents and incorporates the retrieved data directly into the resulting report output generated for the user. Consequently, the attacker gains unauthorized visibility into internal server resources via the generated report interface. The attack flow requires low privileges and successful authentication to the Web Intelligence platform. Exploitation occurs entirely through the application layer by leveraging legitimate administrative or user workflows designed to ingest spreadsheet data sources. Network exposure is contingent upon access to the SAP BusinessObjects Business Intelligence Platform web interface. The post-exploitation impact is strictly limited to a high loss of confidentiality, as sensitive server-side data is exfiltrated through standard reporting mechanisms without affecting data integrity or system availability."
}