CVE-2026-24325

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.
References
Link Resource
https://me.sap.com/notes/3697256 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_enterprise:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2025:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2027:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:14


NVD link : CVE-2026-24325

Mitre link : CVE-2026-24325

CVE.ORG link : CVE-2026-24325


JSON object : View

Products Affected

sap

  • businessobjects_enterprise
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')