CVE-2025-0060

MEDIUM

SAP BusinessObjects - Code Injection

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3474398

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
sap/businessobjects_business_intelligence_platform 420
sap/businessobjects_business_intelligence_platform 430
sap/businessobjects_business_intelligence_platform 2025
Published Jan 14, 2025
Tracked Since Feb 18, 2026