Advisory
On 11.08.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within BI/BO platform.
SAP Note 3753141 addresses "3753141 - [CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence" to prevent xml injection vulnerability with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows an authenticated attacker to upload a spreadsheet containing malicious external references, resulting in unauthorized access to and disclosure of sensitive server-side files within the generated report.
Solution
The component no longer accepts specially crafted Excel files containing malicious external references.
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- ENTERPRISE 430 110
- ENTERPRISE 2025 36
- ENTERPRISE 2027 24
- ENTERPRISECLIENTTOOLS 430 7
- ENTERPRISECLIENTTOOLS 2025 4
- ENTERPRISECLIENTTOOLS 2027 2
