SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.
History

Thu, 23 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap businessobjects Business Intelligence
CPEs cpe:2.3:a:sap:businessobjects_business_intelligence:2025:*:*:*:-:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:2027:*:*:*:-:*:*:*
cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:enterprise:*:*:*
Vendors & Products Sap
Sap businessobjects Business Intelligence

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00094}

epss

{'score': 0.00143}


Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.
Title Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-06-10T00:10:12.042Z

Updated: 2025-06-10T15:27:15.494Z

Reserved: 2025-01-13T11:13:59.547Z

Link: CVE-2025-23192

cve-icon Vulnrichment

Updated: 2025-06-10T14:19:17.281Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-10T01:15:20.847

Modified: 2025-10-23T14:30:12.927

Link: CVE-2025-23192

cve-icon Redhat

No data.