← Back

CVE-2025-23192

nvd nist
Published: Jun 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.3 / Impact: 4.7
Source: NVD

Description

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.

Affected (3)

1 product
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 2025
Version 2027
Version 430

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Patch

Timeline

No history available yet.