CVE-2025-25245

S

AP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:*

History

24 Oct 2025, 18:41

Type Values Removed Values Added
First Time Sap
Sap businessobjects Business Intelligence Platform
References () https://me.sap.com/notes/3557469 - () https://me.sap.com/notes/3557469 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Patch
CPE cpe:2.3:a:sap:businessobjects_business_intelligence_platform:2025:*:*:*:-:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence_platform:430:*:*:*:enterprise:*:*:*

11 Mar 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 01:15

Updated : 2025-10-24 18:41


NVD link : CVE-2025-25245

Mitre link : CVE-2025-25245

CVE.ORG link : CVE-2025-25245


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')