Insufficient Sanitization Vulnerability in SAP BusinessObjects Content Administrator Workbench
CVE-2025-42985

6.1MEDIUM

What is CVE-2025-42985?

A vulnerability exists in the SAP BusinessObjects Content Administrator Workbench due to inadequate sanitization processes. Attackers may exploit this flaw by crafting specially designed URLs that enable the execution of harmful scripts within a user's browser. If exploited, this could lead to unauthorized access to or alteration of web client data, undermining the integrity and confidentiality of the information while maintaining normal application availability.

Affected Version(s)

SAP BusinessObjects Content Administrator workbench DW4CORE 100

SAP BusinessObjects Content Administrator workbench 200

SAP BusinessObjects Content Administrator workbench 300

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42985 : Insufficient Sanitization Vulnerability in SAP BusinessObjects Content Administrator Workbench