CVE-2025-25245: Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25245?
CVE-2025-25245 is classified as a high severity vulnerability due to the potential for remote code execution through an insecure web application endpoint.
How do I fix CVE-2025-25245?
To fix CVE-2025-25245, users should update their SAP BusinessObjects Business Intelligence Platform (Web Intelligence) to the latest version provided by SAP.
What are the implications of CVE-2025-25245 exploitation?
Exploitation of CVE-2025-25245 can lead to an attacker executing unauthorized commands and injecting malicious URLs into data returned to users.
Which versions of SAP BusinessObjects are affected by CVE-2025-25245?
CVE-2025-25245 affects all versions of SAP BusinessObjects Business Intelligence Platform (Web Intelligence) that contain the deprecated web application endpoint.
Is there a workaround for CVE-2025-25245?
Currently, there are no official workarounds for CVE-2025-25245, and upgrading to the patched version is recommended as the best mitigation strategy.