CVE-2025-42985: SAP SE SAP Businessobjects Content Administrator Workbench

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no impact on application availability.

Affected products

  • SAP SE SAP Businessobjects Content Administrator Workbench: version 200 only; version 300 only; version 400 only; version 701 only; version 702 only; version 731 only; …

Published 2025-07-08. Last modified 2026-06-17.