Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3654236
was released on
10.02.2026 and deals with
"[CVE-2026-0490] Denial of service (DOS) in SAP BusinessObjects BI Platform" within BI/BO platform.
We advice you to follow the instructions, to resolve
denial of service (dos)
with a
high potential for exploitation
in component BI-BIP-SRV.
According to SAP Security Advisory team a workaround exists. It is advisable to implement the correction as part of maintenance.
Denial of Service (DoS) attacks that take a system offline may lead to significant cost for the company, studies quantify the costs in average between 4 and 5 millions dollars. Business continuity requires SAP systems staying online. The CVSS scores or vulnerability descriptions are not enough to represent how a simple bug can lead to a significant loss for companies.
Risk specification
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send crafted requests to a trusted endpoint that disrupt the authentication flow, potentially preventing legitimate users from accessing the platform.
Solution
Mutual TLS (mTLS) validation is now supported for the trusted endpoint, ensuring that only requests originating from trusted backend systems are accepted. Alternativly, the consulting team has proposed the following: "The landscape must be segregated into an internal network for the communication of the Web-tier and backend services, and an external network for the user access to the Web-tier. Requests from the external network to the authorized URL must be blocked.". The suggestion may be considered, as a workaround or compensating mitigation. We recommend installing/applying the correction wherever possible and as soon as possible. Base your decision on whether or not to apply the patch on your companies and systems risk perspective and consider the provided CVSS 7.5 score.
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- ENTERPRISE 2025 27
- ENTERPRISE 2027 16
- ENTERPRISE 430 101
