CVE-2025-23192 Details
Description
SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access sensitive session information, modify or make browser information unavailable. This leads to a high impact on confidentiality and low impact on integrity, availability.
A stored cross-site scripting vulnerability has been identified in SAP BusinessObjects Business Intelligence (BI Workspace). This issue allows an unauthenticated attacker to inject malicious scripts into a workspace. When a victim accesses the workspace, the injected script executes in their browser. This execution could enable the attacker to access sensitive session information, alter browser data, or disrupt the availability of browser information. The vulnerability impacts confidentiality significantly, while integrity and availability are affected to a lesser degree.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP for Me platform. This vulnerability will also be addressed in the upcoming SAP Security Patch Day.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3560693 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap businessobjects business intelligence | 430 2025 2027 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | Initial Analysis | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |