cbcvebase.
CVE-2025-23192
published 2025-06-10

CVE-2025-23192: SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the…

high7.6CVSS 3.1
AVNACLPRLUIRSCCHILAN
SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
sapbusinessobjects_business_intelligence
sapbusinessobjects_business_intelligence
sapbusinessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence