HTML Injection Vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2025-31326
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 July 2025
What is CVE-2025-31326?
The SAP BusinessObjects Business Intelligence Platform, specifically the Web Intelligence module, is vulnerable to HTML Injection attacks. This flaw permits users with basic privileges to inject harmful scripts into designated input fields. As a result, attackers can manipulate the application, potentially redirecting users to malicious domains. While the integrity of the system is at risk, this vulnerability does not compromise the confidentiality or availability of the system. Organizations should prioritize updates and patches to mitigate this security risk.
Affected Version(s)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) ENTERPRISE 430
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 2025
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) 2027