HTML Injection Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2025-31326

4.1MEDIUM

What is CVE-2025-31326?

The SAP BusinessObjects Business Intelligence Platform, specifically the Web Intelligence module, is vulnerable to HTML Injection attacks. This flaw permits users with basic privileges to inject harmful scripts into designated input fields. As a result, attackers can manipulate the application, potentially redirecting users to malicious domains. While the integrity of the system is at risk, this vulnerability does not compromise the confidentiality or availability of the system. Organizations should prioritize updates and patches to mitigate this security risk.

Affected Version(s)

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) ENTERPRISE 430

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 2025

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 2027

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31326 : HTML Injection Vulnerability in SAP BusinessObjects Business Intelligence Platform