SAP Patch Day – June 2026

SAP issues monthly Security Patch Day Bulletins on the second Tuesday of every month- which has been synchronized with the Security Patch Day of other major software vendors. This month’s bulletin was issued on June 9, 2026, and contains 15 new security notesTwo of these notes apply to the SAP BusinessObjects Platform and one applies to customers that augment their SAP BusinessObjects landscape with Wily Introscope.

CVE-2026-44755

For more information, review SAP Security Note 3687096 – [CVE-2026-44755] Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform or the original CVE-2026-44755 record.

SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability. This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application.

This vulnerability has a score of 4.3/10 on the Common Vulnerability Scoring System (CVSS) and is classified as medium. It is fixed in the following releases:

  • SAP BusinessObjects BI 4.3 SP4 Patch 17 (no longer under patch support)

  • SAP BusinessObjects BI 4.3 SP5 Patch 6 (released May 22, 2026)

  • SAP BusinessObjects BI 2025 SP0 Patch 11 (released May 29, 2026)

CVE-2026-44743

For more information, review SAP Security Note 3706000 – [CVE-2026-44743] Security Misconfiguration vulnerability in SAP Business Objects or the original CVE-2026-44743 record.

Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information. This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application.

This vulnerability has a score of 3.7/10 on the Common Vulnerability Scoring System (CVSS) and is classified as low. It is fixed in the following releases:

  • SAP BusinessObjects BI 4.3 SP5 Patch 6 (released May 22, 2026)

  • SAP BusinessObjects BI 2025 SP0 Patch 0 (released March 12, 2025)

CVE-2026-44757

This vulnerability is for Wily Introscope Enterprise Manager. Wily Introscope is an application performance management (APM) tool used to monitor, trace, and diagnose the performance of Java and enterprise applications in real time. SAP does not own Introscope, but it bundles and integrates a limited version with SAP Solution Manager and other SAP products like SAP BusinessObjects.

For more information, review SAP Security Note 3715280 – [CVE-2026-44757] Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager or the original CVE-2026-44757 record.

SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected script could execute in the user’s browser within the context of the application. This issue has a low impact on the confidentiality and integrity of the application with no impact on availability.

This vulnerability has a score of 4.7/10 on the Common Vulnerability Scoring System (CVSS) and is classified as medium. It is fixed in the following releases:

  • Wily Introscope Enterprise Manager SP02 patch 0 (10.8.0.230) or higher

Apache Tomcat vulnerabilities NOT impacting SAP BI Platform

When your organization’s security team identifies vulnerabilities in Apache Tomcat, you’ll want to review SAP Note 2498770 – Tomcat vulnerabilities (CVE-*) NOT impacting SAP BI Platform to provide documentation that a patch is not needed for the SAP BI Platform.

As an added bonus to patching for CVE, updating BI 4.3 to SP5 Patch 3 or higher or BI 2025 to SP0 Patch 7 or higher will automatically update Apache Tomcat to version 9.0.111 (see SAP KB 2112338 – List of Bundled Tomcat and JVM versions shipped with each SP of SAP BusinessObjects Business Intelligence Platform).

Third-party software vulnerabilities NOT impacting SAP BusinessObjects

The SAP BusinessObjects platform uses multiple third-party software products. In addition to the list above for Apache Tomcat, review SAP Note 2914574 – Third-party software vulnerabilities (CVE) NOT impacting SAP BusinessObjects to provide documentation that a patch is not needed for the SAP BI Platform.

Recommendation

InfoSol recommends patching to either BI 4.3 SP5 Patch 6 and higher or BI 2025 SP0 Patch 9 and higher for any SAP BusinessObjects customer operating below those patch levels. As always, review SAP’s release notes and patch upgrade guide, which are available on the SAP Help Portal.

Whether you choose BI 4.3 or BI 2025 will largely be determined by whether your organization still uses “classic” UNV universes. These universes are no longer supported in BI 2025 and must be converted to UNX format prior to upgrading to BI 2025. Choosing BI 4.3 or BI 2025 also depends on the age of your hardware and operating system, as many organizations adopting BI 2025 will likely want to deploy it on new hardware using the latest supported version of Windows Server.

IMPORTANT: Support packs prior to BI 4.3 SP5 are no longer under patch support. Customers on BI 4.3 SP4 and earlier (this includes SAP BusinessObjects BI 4.2) should consider patching, as earlier versions are affected by security vulnerabilities.

IMPORTANT: InfoSol does not recommend BI 4.3 SP5 Patch 4 or BI 2025 SP0 Patch 8, as these patch levels were affected by a CMS clustering issue described in SAP Note 3724948.

InfoBurst

InfoSol also recommends that its InfoBurst customers use this opportunity to upgrade to version 2026.1.1. InfoBurst software can be downloaded from the InfoSol Help Portal.

Previous SAP Security articles from Speak BO

How InfoSol Can Help

Don’t wait for vulnerabilities to become disruptions. With this month’s SAP Security Patch Day introducing several high‑priority updates, now is the perfect time to take a strategic approach to your BusinessObjects environment. InfoSol can help you move beyond reactive patching by assessing your current risk posture, streamlining your update process, and aligning your platform with SAP’s long‑term roadmap. From stabilizing existing BI 4.x deployments to guiding upgrades into BI 2025 and accelerating your shift to UNX universes, our team delivers practical, hands‑on expertise every step of the way. Let’s turn patching into an opportunity to strengthen performance, security, and future readiness.

Contact InfoSol today to schedule a free patching assessment or upgrade consultation—and ensure your BI environment stays protected, optimized, and compliant.

About Dallas Marks

Dallas is a BI Technical Consultant at InfoSol, where he delivers consulting and training services focused on SAP BusinessObjects and information delivery. He is also a product specialist for InfoBurst and Squirrel365, helping organizations automate and scale their reporting processes. Dallas is a frequent contributor to the Speak BO community, sharing practical insights and real-world solutions.

Check Also

IBIS 2026 Dove Mountain Resort Night View

IBIS 2027 Save the Date: June 14-16

If you want to explore everything that’s happening with BusinessObjects and learn from top global …

Leave a Reply

Your email address will not be published. Required fields are marked *