Description
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 14 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability. | |
| Title | Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-04-14T00:08:15.599Z
Reserved: 2026-02-23T17:50:17.028Z
Link: CVE-2026-27683
No data.
Status : Received
Published: 2026-04-14T00:16:06.717
Modified: 2026-04-14T00:16:06.717
Link: CVE-2026-27683
No data.
OpenCVE Enrichment
No data.
Weaknesses