CVE-2026-24325

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.
References
Link Resource
https://me.sap.com/notes/3697256 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:businessobjects_enterprise:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2025:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2027:*:*:*:*:*:*:*

History

17 Feb 2026, 15:14

Type Values Removed Values Added
References () https://me.sap.com/notes/3697256 - () https://me.sap.com/notes/3697256 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
First Time Sap
Sap businessobjects Enterprise
Summary
  • (es) SAP BusinessObjects Enterprise no codifica suficientemente las entradas controladas por el usuario, lo que lleva a una vulnerabilidad de cross-site scripting (XSS) almacenado. Esto permite a un usuario administrador inyectar JavaScript malicioso en un sitio web y el script inyectado se ejecuta cuando el usuario visita la página comprometida. Esta vulnerabilidad tiene bajo impacto en la confidencialidad e integridad de los datos. No hay impacto en la disponibilidad de la aplicación.
CPE cpe:2.3:a:sap:businessobjects_enterprise:2025:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:430:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_enterprise:2027:*:*:*:*:*:*:*

10 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:14


NVD link : CVE-2026-24325

Mitre link : CVE-2026-24325

CVE.ORG link : CVE-2026-24325


JSON object : View

Products Affected

sap

  • businessobjects_enterprise
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')