Severity
6.1MEDIUMNVD
CNA10.0CISA7.2
EPSS
1.0%
top 22.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateDec 30

Description

Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens those reports would be susceptible to stored XSS attacks. As a result of the attack, information maintained in the victim's web browser can be read, modified, and sent to the attacker.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

6
OSV
quota: fix warning in dqgrab()2025-12-30
OSV
cifs: fix potential oops in cifs_oplock_break2025-12-30
OSV
hfs: fix missing hfs_bnode_get() in __hfs_bnode_create2025-12-09
OSV
drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend2025-10-22
CVEList
Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)2023-01-10

📋Vendor Advisories

5
Red Hat
kernel: hfs: fix missing hfs_bnode_get() in __hfs_bnode_create2025-12-09
Red Hat
kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue2025-09-16
Red Hat
kernel: scsi: qla2xxx: Synchronize the IOCB count to be in order2025-05-02
CISA
SonicWall SMA100 Appliances OS Command Injection Vulnerability2025-05-01
Red Hat
kernel: scsi: qedi: Fix crash while reading debugfs attribute2024-07-12
CVE-2023-0018 — Cross-site Scripting in SAP | cvebase