CVE-2025-0064 | Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.
Conclusion & alert: CVE-2025-0064 is rated Moderate Risk (40.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2025-0064
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).