We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-31326

HTML Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)



Description

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application behavior, such as redirecting users to attacker-controlled domains. This issue primarily affects the integrity of the system. However, the confidentiality and availability of the system remain unaffected.

Reserved 2025-03-27 | Published 2025-07-08 | Updated 2025-07-08 | Assigner sap


MEDIUM: 4.1CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Problem types

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page

Product status

Default status
unaffected

ENTERPRISE 430
affected

2025
affected

2027
affected

ENTERPRISECLIENTTOOLS 430
affected

References

me.sap.com/notes/3573199

url.sap/sapsecuritypatchday

cve.org (CVE-2025-31326)

nvd.nist.gov (CVE-2025-31326)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-31326

Support options

Helpdesk Chat, Email, Knowledgebase