CVE 4.8 MEDIUM

Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console)_CVE-2026-24325

4.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Description

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

Basic Information

ID CVE-2026-24325
Source sap
Published Feb 10, 2026 at 03:04

Affected Product

Vendor SAP_SE
Product SAP BusinessObjects Enterprise (Central Management Console)
Version ENTERPRISE 430
Affected Versions SAP_SE SAP BusinessObjects Enterprise (Central Management Console) ENTERPRISE 430
SAP_SE SAP BusinessObjects Enterprise (Central Management Console) 2025
SAP_SE SAP BusinessObjects Enterprise (Central Management Console) 2027

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.