Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-31332

CVE-2025-31332: SAP BusinessObjects BI Platform DoS Flaw

CVE-2025-31332 is a denial of service vulnerability in SAP BusinessObjects Business Intelligence Platform caused by insecure file permissions. Attackers with local access can disrupt operations. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2025-31332 Overview

CVE-2025-31332 is an insecure file permissions vulnerability in SAP BusinessObjects Business Intelligence Platform. A local, authenticated attacker with low privileges can modify files that should be protected by stricter access controls. Successful exploitation disrupts platform operations and can cause service downtime, producing high impact on integrity and availability. The vulnerability does not expose sensitive data. SAP assigned this issue a CVSS v3.1 base score of 7.1 and mapped it to [CWE-277: Insecure Inherited Permissions]. Version 430 (Enterprise) of the platform is listed as affected in the National Vulnerability Database entry.

Critical Impact

A local attacker with low privileges can alter protected BusinessObjects files, disrupt reporting operations, and force service downtime across the BI platform.

Affected Products

  • SAP BusinessObjects Business Intelligence Platform 430 (Enterprise)
  • Deployments identified by CPE cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
  • Any host running the affected release where non-administrative local accounts exist

Discovery Timeline

  • 2025-04-08 - CVE-2025-31332 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in the National Vulnerability Database

Technical Details for CVE-2025-31332

Vulnerability Analysis

The vulnerability results from file system objects installed or created by SAP BusinessObjects Business Intelligence Platform receiving permissions that are broader than required. Local users who should not have write access to platform files can modify them. This condition falls under [CWE-277], which covers cases where files inherit permissions that grant unintended actors the ability to change protected data.

Attackers do not need to authenticate remotely. They need only interactive or shell access to the host running BusinessObjects. Because the flaw affects integrity and availability, an attacker can alter configuration files, binaries, or supporting resources that the BusinessObjects services depend on at startup or runtime.

The result is service disruption. Modified files can cause components to fail, produce inconsistent report output, or refuse to start. SAP notes in the advisory that confidentiality is not affected, so this issue is scoped to tampering and denial of service rather than data theft.

Root Cause

The root cause is the assignment of overly permissive access control entries to platform files during installation or normal operation. Standard operating system accounts that should be restricted to read or execute rights receive write rights on files owned by the BusinessObjects service context.

Attack Vector

Exploitation requires local access with low-privileged credentials and no user interaction. An attacker logs into the server, identifies writable files belonging to the BusinessObjects installation, and replaces or edits them. On the next service restart or file read, the tampered content is loaded, causing the platform to misbehave or halt.

No verified public exploit or proof of concept has been published for CVE-2025-31332. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and current EPSS data indicates a low probability of exploitation attempts in the near term.

Detection Methods for CVE-2025-31332

Indicators of Compromise

  • Unexpected modification timestamps on files under the SAP BusinessObjects installation directory
  • BusinessObjects services failing to start, crashing, or serving inconsistent report output after routine local user activity
  • New or altered configuration files not associated with a documented change ticket or SAP patch

Detection Strategies

  • Baseline the file hashes and access control lists of the BusinessObjects installation tree, then alert on any deviation
  • Enable operating system file integrity monitoring on directories containing BusinessObjects binaries, scripts, and configuration files
  • Correlate local logon events with subsequent write operations against BusinessObjects files owned by the service account

Monitoring Recommendations

  • Forward operating system audit logs, file integrity events, and BusinessObjects service logs to a centralized log platform for correlation
  • Review privileged and interactive logon activity on BusinessObjects hosts on a recurring schedule
  • Track SAP Security Patch Day releases and confirm patch deployment status against monitored hosts

How to Mitigate CVE-2025-31332

Immediate Actions Required

  • Apply the fix described in SAP Note #3565751 as published on SAP Security Patch Day
  • Restrict interactive and remote shell access to BusinessObjects servers to administrators only
  • Audit local accounts on affected hosts and remove accounts that are not required for operation or maintenance

Patch Information

SAP addressed CVE-2025-31332 through the fix documented in SAP Note #3565751. Administrators should authenticate to the SAP Support Portal, review the note, and apply the corrective actions to SAP BusinessObjects Business Intelligence Platform 430. Additional context is available on the SAP Security Patch Day page.

Workarounds

  • Manually tighten file system permissions on the BusinessObjects installation directory so that only the service account and administrators hold write access
  • Enforce least privilege on the operating system by removing shell and file system access for non-administrative users on BI hosts
  • Enable file integrity monitoring as a compensating control until the SAP-provided fix is deployed

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.