Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.