CVE-2026-0485 describes a denial-of-service vulnerability in SAP BusinessObjects BI Platform, allowing unauthenticated attackers to crash and repeatedly restart the Content Management Server (CMS) through specially crafted requests. This vulnerability has a high severity CVSS score of 7.5, indicating a network-based attack with low complexity that results in a high impact on availability. While confidentiality and integrity are unaffected, persistent service disruption can render the CMS completely unavailable. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
430CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:enterprise:*:*:* | ||
2027CPE matchmatch criteria | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2027:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.