Home

Description

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application behavior, such as redirecting users to attacker-controlled domains. This issue primarily affects the integrity of the system. However, the confidentiality and availability of the system remain unaffected.

PUBLISHED Reserved 2025-03-27 | Published 2025-07-08 | Updated 2025-07-08 | Assigner sap




MEDIUM: 4.1CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Problem types

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page

Product status

Default status
unaffected

ENTERPRISE 430
affected

2025
affected

2027
affected

ENTERPRISECLIENTTOOLS 430
affected

References

me.sap.com/notes/3573199

url.sap/sapsecuritypatchday

cve.org (CVE-2025-31326)

nvd.nist.gov (CVE-2025-31326)

Download JSON