SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1490 | SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap businessobjects Business Intelligence Platform |
|
| CPEs | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:420:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:-:*:*:* |
|
| Vendors & Products |
Sap
Sap businessobjects Business Intelligence Platform |
Tue, 14 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application. | |
| Title | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-01-14T14:59:23.756Z
Reserved: 2024-12-05T21:53:03.846Z
Link: CVE-2025-0060
Updated: 2025-01-14T14:58:56.871Z
Status : Analyzed
Published: 2025-01-14T01:15:16.350
Modified: 2025-10-24T19:15:58.383
Link: CVE-2025-0060
No data.
OpenCVE Enrichment
No data.
EUVD