JavaScript Injection Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2025-0060
Currently unrated
Summary
The SAP BusinessObjects Business Intelligence Platform contains a vulnerability that allows an authenticated user with restricted access to inject malicious JavaScript code. This code can read sensitive information from the server and transmit it to an attacker. Consequently, the attacker may use the captured data to impersonate high-privileged users, severely compromising the confidentiality and integrity of the application. Organizations using affected versions should take immediate steps to safeguard their data and prevent unauthorized access.
References
Timeline
Vulnerability published