CVE-2025-24867: Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad)
SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be executed in the browser, giving the attacker the ability to access and/or modify information related to the web client with no effect on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24867?
CVE-2025-24867 has a high severity rating due to the potential for unauthorized user input leading to Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-24867?
To fix CVE-2025-24867, ensure you are using the latest version of the SAP BusinessObjects Platform that includes the security patch addressing this vulnerability.
Who is affected by CVE-2025-24867?
CVE-2025-24867 affects users of the SAP BusinessObjects Business Intelligence platform that do not properly manage user input.
What type of attack can be executed due to CVE-2025-24867?
CVE-2025-24867 can be exploited through Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Can CVE-2025-24867 be exploited remotely?
Yes, CVE-2025-24867 can be exploited remotely by unauthenticated attackers who craft a URL with malicious scripts.