SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3474398 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
24 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| First Time |
Sap
Sap businessobjects Business Intelligence Platform |
|
| CPE | cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:-:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:420:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:* |
|
| References | () https://me.sap.com/notes/3474398 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch |
14 Jan 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-14 01:15
Updated : 2025-10-24 19:15
NVD link : CVE-2025-0060
Mitre link : CVE-2025-0060
CVE.ORG link : CVE-2025-0060
JSON object : View
Products Affected
sap
- businessobjects_business_intelligence_platform
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
