CVE-2026-24325

MEDIUM

SAP BusinessObjects Enterprise - XSS

Title source: llm
STIX 2.1

Description

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3697256

Scores

CVSS v3 4.8
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
sap/businessobjects_enterprise 430
sap/businessobjects_enterprise 2025
sap/businessobjects_enterprise 2027
Published Feb 10, 2026
Tracked Since Feb 18, 2026