CVE-2026-27683: Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27683?
CVE-2026-27683 is rated as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2026-27683?
To fix CVE-2026-27683, update your SAP BusinessObjects Business Intelligence Platform to the latest patched version provided by SAP.
Who is affected by CVE-2026-27683?
CVE-2026-27683 affects authenticated users of SAP BusinessObjects Business Intelligence Platform.
What type of attack does CVE-2026-27683 enable?
CVE-2026-27683 enables an attacker to carry out reflected cross-site scripting attacks by injecting malicious JavaScript payloads via crafted URLs.
How can I prevent exploitation of CVE-2026-27683?
To prevent exploitation of CVE-2026-27683, ensure that URL inputs are properly validated and sanitized in your web applications.