August 7, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-0502NVD

Vulnerability Summary

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data.
Severity Level
MEDIUM(5.4)
Published Date
May 12, 2026
Last Modified
May 12, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.01%Probability
Root Weakness (CWE)
The web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityLow