CVE-2025-0060
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 94
Summary
CVE-2025-0060 is a vulnerability affecting the SAP BusinessObjects Business Intelligence Platform. It allows authenticated users with restricted access to inject malicious JavaScript code. This code can then be used to read sensitive information from the server and transmit it to unauthorized attackers. The implications of this vulnerability are significant, as an attacker could potentially impersonate a high-privileged user, leading to a high impact on the confidentiality and integrity of the application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.