CyberRota Analysis
AI-GeneratedSAP BusinessObjects Business Intelligence Platform (Web Intelligence) is vulnerable to a low-privileged attacker who can upload a specially crafted spreadsheet file that contains malicious external references. When processed, this can lead to the exposure of sensitive server-side file contents in the generated report, significantly compromising confidentiality. Organizations using this platform should prioritize addressing this vulnerability to protect sensitive data from unauthorized access.
Original NVD Description
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.