First published: Tue Jan 14 2025(Updated: )
SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0060 is classified as a high severity vulnerability due to its potential for sensitive data exposure.
To fix CVE-2025-0060, apply the latest security patches provided by SAP for the BusinessObjects Business Intelligence Platform.
CVE-2025-0060 affects users of SAP BusinessObjects Business Intelligence Platform who have authenticated access.
CVE-2025-0060 is associated with a cross-site scripting (XSS) attack that allows the injection of malicious JavaScript code.
An attacker exploiting CVE-2025-0060 can read sensitive information from the server, potentially leading to user impersonation.