JavaScript Injection Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2025-0060

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 January 2025

Summary

The SAP BusinessObjects Business Intelligence Platform contains a vulnerability that allows an authenticated user with restricted access to inject malicious JavaScript code. This code can read sensitive information from the server and transmit it to an attacker. Consequently, the attacker may use the captured data to impersonate high-privileged users, severely compromising the confidentiality and integrity of the application. Organizations using affected versions should take immediate steps to safeguard their data and prevent unauthorized access.

References

Timeline

  • Vulnerability published

.