SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3560693 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
23 Oct 2025, 14:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence:2025:*:*:*:-:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence:2027:*:*:*:-:*:*:* |
|
| First Time |
Sap businessobjects Business Intelligence
Sap |
|
| References | () https://me.sap.com/notes/3560693 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch |
12 Jun 2025, 16:06
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-06-10 01:15
Updated : 2025-10-23 14:30
NVD link : CVE-2025-23192
Mitre link : CVE-2025-23192
CVE.ORG link : CVE-2025-23192
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
