CVE-2025-0060

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 94

Summary

CVE-2025-0060 is a vulnerability affecting the SAP BusinessObjects Business Intelligence Platform. It allows authenticated users with restricted access to inject malicious JavaScript code. This code can then be used to read sensitive information from the server and transmit it to unauthorized attackers. The implications of this vulnerability are significant, as an attacker could potentially impersonate a high-privileged user, leading to a high impact on the confidentiality and integrity of the application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share