Stored Cross-Site Scripting in SAP BusinessObjects Enterprise
CVE-2026-24325
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-24325?
The SAP BusinessObjects Enterprise product exposes a vulnerability related to the inadequate encoding of user-controlled inputs, resulting in a Stored Cross-Site Scripting (XSS) issue. This weakness allows an administrator to inject harmful JavaScript code into web pages. Consequently, whenever a user accesses the affected page, the malicious script executes, compromising their interaction with the site. While this vulnerability does not significantly threaten the confidentiality or integrity of the data, it poses a risk to user trust and site integrity.
Affected Version(s)
SAP BusinessObjects Enterprise (Central Management Console) ENTERPRISE 430
SAP BusinessObjects Enterprise (Central Management Console) 2025
SAP BusinessObjects Enterprise (Central Management Console) 2027