SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.
                
            References
                    | Link | Resource | 
|---|---|
| https://me.sap.com/notes/3560693 | Permissions Required | 
| https://url.sap/sapsecuritypatchday | Patch | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    23 Oct 2025, 14:30
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://me.sap.com/notes/3560693 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| First Time | Sap Sap businessobjects Business Intelligence | |
| CPE | cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:enterprise:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence:2027:*:*:*:-:*:*:* cpe:2.3:a:sap:businessobjects_business_intelligence:2025:*:*:*:-:*:*:* | 
12 Jun 2025, 16:06
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
10 Jun 2025, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-10 01:15
Updated : 2025-10-23 14:30
NVD link : CVE-2025-23192
Mitre link : CVE-2025-23192
CVE.ORG link : CVE-2025-23192
JSON object : View
Products Affected
                sap
- businessobjects_business_intelligence
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
