Логотип exploitDog
bind:CVE-2025-25245
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25245

Количество 3

Количество 3

nvd логотип

CVE-2025-25245

11 месяцев назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v629-5xqh-x8rp

11 месяцев назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2025-03627

11 месяцев назад

Уязвимость компонента Web Intelligence платформы бизнес-аналитики SAP BusinessObjects Business Intelligence Platform, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-25245

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-v629-5xqh-x8rp

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03627

Уязвимость компонента Web Intelligence платформы бизнес-аналитики SAP BusinessObjects Business Intelligence Platform, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу