Sceawere
Vulnerability Detail
CVE-2026-66763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SAP BusinessObjects Hard-Coded Cryptographic Key Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.9
- Creation Date
- 4h ago
- Vendor
- SAP_SE
- Product
- SAP BusinessObjects Business Intelligence Platform (Central Management Server)
- Attack Type
- CWE-321: Use of Hard-coded Cryptographic Key
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.9",
"pubDate": "2026-08-11T01:17:23.000Z",
"pubdate": "2026-08-11T01:17:23.000Z",
"executiveSummary": "An information disclosure and credential compromise vulnerability exists within the SAP BusinessObjects Business Intelligence Platform related to the management of sensitive cryptographic secrets.\nThe root cause of the vulnerability stems from the utilization of a hard-coded cryptographic key embedded within the application logic to encrypt sensitive credentials associated with user objects.\nSuccessful exploitation of this security flaw allows an authenticated adversary with high privileges and local access to the underlying server to systematically extract these stored user objects and leverage the hard-coded key to successfully decrypt sensitive authentication data.\nThe realization of this attack results in a high impact on both system confidentiality and data integrity, as unauthorized actors can harvest sensitive credentials and subsequently modify protected system information.\nThere is no direct impact on system availability resulting from the exploitation of this specific vulnerability.\nPrerequisites for a successful attack include local server access and possession of high-level administrative privileges within the environment, which significantly restricts the external attack surface but poses a severe internal threat vector or risk from compromised privileged accounts.",
"technicalDetails": "The vulnerability resides in the credential management subsystem of the SAP BusinessObjects Business Intelligence Platform, specifically within the cryptographic routines responsible for protecting sensitive user credentials.\nThe core architectural defect is the implementation of a static, hard-coded cryptographic key utilized across installations to perform encryption and decryption operations on sensitive authentication artifacts associated with user objects.\nBecause the cryptographic key is hard-coded within the application binaries or configuration components, it can be extracted through reverse engineering or static analysis of the software installation by an unauthorized party possessing local system access.\nThe attack flow proceeds as follows: First, the adversary obtains high-privileged access to the host server hosting the SAP BusinessObjects Business Intelligence Platform, either through legitimate administrative abuse, credential theft, or a separate privilege escalation vector.\nSecond, the attacker locates and accesses the stored user objects and encrypted credential stores residing within the platform's data repositories or file structures.\nThird, utilizing the statically analyzed or extracted hard-coded cryptographic key, the attacker executes decryption algorithms against the retrieved ciphertext.\nFourth, this decryption process yields plaintext sensitive authentication data, such as administrative passwords or integration credentials.\nFinally, armed with this sensitive authentication data, the malicious actor can perform post-exploitation activities, including unauthorized authentication to dependent services, privilege escalation within the platform, and the modification of protected system information, leading to severe compromise of confidentiality and integrity.\nThe vulnerability requires local access and high privileges, meaning network exposure alone is insufficient to trigger the flaw without prior compromise of host-level administrative controls."
}