CVE-2024-28165: SAP Businessobjects Business Intelligence Platform

Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application

Affected products

  • SAP Businessobjects Business Intelligence Platform: version 430 only; version 440 only

Published 2024-05-14. Last modified 2026-06-17.