First published: Tue Feb 11 2025(Updated: )
SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be executed in the browser, giving the attacker the ability to access and/or modify information related to the web client with no effect on availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24867 has a high severity rating due to the potential for unauthorized user input leading to Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-24867, ensure you are using the latest version of the SAP BusinessObjects Platform that includes the security patch addressing this vulnerability.
CVE-2025-24867 affects users of the SAP BusinessObjects Business Intelligence platform that do not properly manage user input.
CVE-2025-24867 can be exploited through Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Yes, CVE-2025-24867 can be exploited remotely by unauthenticated attackers who craft a URL with malicious scripts.