PT-2025-24583 · Sap · Sap Businessobjects Business Intelligence

Published

2025-06-10

·

Updated

2025-06-10

·

CVE-2025-23192

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects Business Intelligence (BI Workspace) (affected versions not specified)
Description The issue allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser, enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-06761
CVE-2025-23192

Affected Products

Sap Businessobjects Business Intelligence