SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability. | |
Title | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-03-11T00:34:56.115Z
Updated: 2025-03-11T02:10:07.773Z
Reserved: 2025-02-04T23:28:33.503Z
Link: CVE-2025-25245

Updated: 2025-03-11T02:10:01.160Z

Status : Received
Published: 2025-03-11T01:15:35.080
Modified: 2025-03-11T01:15:35.080
Link: CVE-2025-25245

No data.