← Vulnerability feed

Vulnerability record · CVE-2024-41730 · published 13 August 2024

CVE-2024-41730: SAP BusinessObjects BI Platform missing authorization allows logon token theft

Sap · Business Objects Business Intelligence Platform

SAP BusinessObjects Business Intelligence Platform fails to enforce authorization on a REST endpoint when Single Sign-On is enabled for Enterprise authentication. An unauthenticated attacker can request a logon token and use it to take over the system. The flaw is a missing authorization check (CWE-862) with a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 76% · top 0.5% CWE-862 · Missing authorization
9.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS probability make this a top remediation priority despite no confirmed in-the-wild exploitation.

What it is

SAP BusinessObjects Business Intelligence Platform fails to enforce authorization on a REST endpoint when Single Sign-On is enabled for Enterprise authentication. An unauthenticated attacker can request a logon token and use it to take over the system. The flaw is a missing authorization check (CWE-862) with a critical CVSS score of 9.8.

Impact

An attacker obtains a valid logon token and can fully compromise the system, with high impact on confidentiality, integrity and availability. This effectively grants the attacker the privileges of the token holder without needing credentials.

Attack surface

Reachable over the network via a REST endpoint with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). Exploitation depends on Single Sign-On being enabled on Enterprise authentication, so only deployments with that configuration are exposed.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.759 (99.5th percentile), indicating strong likelihood of attempted exploitation. The SAP reference is a vendor advisory and the SAP note requires permissions to view, so no public exploit details are confirmed in this record.

What to do

  • Apply the SAP security patch referenced in SAP note 3479478 and the SAP Security Patch Day advisory as soon as possible.
  • If patching cannot be immediate, disable Single Sign-On on Enterprise authentication or restrict access to the affected REST endpoint until the fix is applied.
  • Restrict network access to SAP BusinessObjects BI REST endpoints to trusted hosts and management networks.
  • Review and rotate credentials or tokens that may have been issued through the vulnerable endpoint.
  • Monitor SAP security notes for updated guidance and confirm the affected product versions from the vendor advisory.

Detection

  • Monitor REST endpoint access logs for logon token requests from unauthenticated or unexpected source IPs.
  • Alert on token issuance events that occur outside normal authentication flows or from anomalous user agents.
  • Correlate SAP BusinessObjects authentication logs for token use from IP addresses that never completed a normal login.
  • Hunt for unusual administrative or data-access activity following token issuance on SSO-enabled Enterprise authentication deployments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://me.sap.com/notes/3479478 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory

Track CVE-2024-41730 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-25616Sap business objects business intelligence platform injection vulnerabilityIn some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection …EPSS 0.95%8.8CVE-2023-25617Sap business objects business intelligence platform os command injection vulnerabilitySAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution …EPSS 0.93%8.8CVE-2022-41267Sap business objects business intelligence platform unrestricted file upload vulnerabilitySAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec…EPSS 0.82%7.6CVE-2023-42478Sap business objects business intelligence platform cross-site scripting vulnerabilitySAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which…EPSS 0.56%7.6CVE-2022-39013Sap business objects business intelligence platform information exposure vulnerabilityUnder certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify …EPSS 0.67%6.5CVE-2022-39015Sap business objects business intelligence platform exposure of resource to wrong sphere vulnerabilityUnder certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.EPSS 0.84%6.5CVE-2022-24398Sap business objects business intelligence platform information exposure vulnerabilityUnder certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat…EPSS 0.80%6.0CVE-2022-31596Sap business objects business intelligence platform exposure of resource to wrong sphere vulnerabilityUnder certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Busi…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2024-41730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.