CVE-2024-28165: SAP Businessobjects Business Intelligence Platform
Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
Affected products
- SAP Businessobjects Business Intelligence Platform: version 430 only; version 440 only
Published 2024-05-14. Last modified 2026-06-17.