cbcvebase.
CVE-2025-23192
published 2025-06-10

CVE-2025-23192: SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the…

PriorityP342high7.6CVSS 3.1
AVNACLPRLUIRSCCHILAN
EPSS
0.34%
26.4th percentile
SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
sapbusinessobjects_business_intelligence
sapbusinessobjects_business_intelligence
sapbusinessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence
sap_sesap_businessobjects_business_intelligence

CVSS provenance

nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.