CVE-2025-25245

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:*

History

24 Oct 2025, 18:41

Type Values Removed Values Added
References () https://me.sap.com/notes/3557469 - () https://me.sap.com/notes/3557469 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Patch
Summary
  • (es) SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contiene un endpoint de aplicación web obsoleto que no está protegido adecuadamente. Un atacante podría aprovechar esto inyectando una URL maliciosa en los datos que se devuelven al usuario. Si se explota con éxito, podría haber un impacto limitado en la confidencialidad e integridad dentro del alcance del navegador de la víctima. No hay impacto en la disponibilidad.
First Time Sap
Sap businessobjects Business Intelligence Platform
CPE cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:*

11 Mar 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 01:15

Updated : 2025-10-24 18:41


NVD link : CVE-2025-25245

Mitre link : CVE-2025-25245

CVE.ORG link : CVE-2025-25245


JSON object : View

Products Affected

sap

  • businessobjects_business_intelligence_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')