Vulnerability record · CVE-2024-41730 · published 13 August 2024
CVE-2024-41730: SAP BusinessObjects BI Platform missing authorization allows logon token theft
Sap · Business Objects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform fails to enforce authorization on a REST endpoint when Single Sign-On is enabled for Enterprise authentication. An unauthenticated attacker can request a logon token and use it to take over the system. The flaw is a missing authorization check (CWE-862) with a critical CVSS score of 9.8.
Description
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS probability make this a top remediation priority despite no confirmed in-the-wild exploitation.
What it is
SAP BusinessObjects Business Intelligence Platform fails to enforce authorization on a REST endpoint when Single Sign-On is enabled for Enterprise authentication. An unauthenticated attacker can request a logon token and use it to take over the system. The flaw is a missing authorization check (CWE-862) with a critical CVSS score of 9.8.
Impact
An attacker obtains a valid logon token and can fully compromise the system, with high impact on confidentiality, integrity and availability. This effectively grants the attacker the privileges of the token holder without needing credentials.
Attack surface
Reachable over the network via a REST endpoint with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). Exploitation depends on Single Sign-On being enabled on Enterprise authentication, so only deployments with that configuration are exposed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.759 (99.5th percentile), indicating strong likelihood of attempted exploitation. The SAP reference is a vendor advisory and the SAP note requires permissions to view, so no public exploit details are confirmed in this record.
What to do
- Apply the SAP security patch referenced in SAP note 3479478 and the SAP Security Patch Day advisory as soon as possible.
- If patching cannot be immediate, disable Single Sign-On on Enterprise authentication or restrict access to the affected REST endpoint until the fix is applied.
- Restrict network access to SAP BusinessObjects BI REST endpoints to trusted hosts and management networks.
- Review and rotate credentials or tokens that may have been issued through the vulnerable endpoint.
- Monitor SAP security notes for updated guidance and confirm the affected product versions from the vendor advisory.
Detection
- Monitor REST endpoint access logs for logon token requests from unauthenticated or unexpected source IPs.
- Alert on token issuance events that occur outside normal authentication flows or from anomalous user agents.
- Correlate SAP BusinessObjects authentication logs for token use from IP addresses that never completed a normal login.
- Hunt for unusual administrative or data-access activity following token issuance on SSO-enabled Enterprise authentication deployments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://me.sap.com/notes/3479478 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
Track CVE-2024-41730 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-41730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.